feat: read-only FHIR R4 server (share records over /fhir)

Expose temetro's own records as a read-only FHIR R4 server at /fhir,
authenticated with per-clinic API keys (tmf_… bearer tokens, SHA-256
hashed, shown once). Serves Patient, Observation (labs + vitals),
AllergyIntolerance, Condition, MedicationRequest, Encounter and
Appointment as text-only CodeableConcepts (temetro stores free-text
clinical values); CapabilityStatement at /fhir/metadata (unauth).
Searchset Bundles with _count/_offset pagination and self/next/prev
links; every request is org-scoped and written to the activity log.
Keys are created/revoked under Settings → Integrations (owner/admin).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Khalid Abdi
2026-07-04 01:27:32 +03:00
parent bb536ba6da
commit 0d2494d67a
23 changed files with 6230 additions and 1 deletions
+31
View File
@@ -64,6 +64,37 @@ export function submitInsuranceClaim(
});
}
// --- FHIR server API keys (owner/admin only) --------------------------------
export type FhirApiKey = {
id: string;
name: string;
createdAt: string;
lastUsedAt: string | null;
revoked: boolean;
};
// A freshly created key includes the one-time plaintext secret; it is never
// returned again.
export type CreatedFhirApiKey = FhirApiKey & { secret: string };
export function listFhirKeys(): Promise<FhirApiKey[]> {
return apiFetch<FhirApiKey[]>("/api/integrations/fhir-server/keys");
}
export function createFhirKey(name: string): Promise<CreatedFhirApiKey> {
return apiFetch<CreatedFhirApiKey>("/api/integrations/fhir-server/keys", {
method: "POST",
body: JSON.stringify({ name }),
});
}
export function revokeFhirKey(id: string): Promise<{ revoked: boolean }> {
return apiFetch(`/api/integrations/fhir-server/keys/${id}`, {
method: "DELETE",
});
}
// Convenience hook-style fetch reused by the on-page sections: returns the
// config for one type (or null while loading/absent).
export async function getIntegration(