# GSoC 2020: Advancement of OAuth2 Module and Improvements in SMART OWA

**URL:** <https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651>\
**Category:** GSoC\
**Tags:** oauth2\
**Created:** [March 27, 2020, 10:10am UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651 "2020-03-27T10:10:49Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![joachimjunior](https://talk.openmrs.org/user_avatar/talk.openmrs.org/joachimjunior/32/14667_2.png) [@joachimjunior](https://talk.openmrs.org/u/joachimjunior)\
**Post date:** [March 27, 2020, 10:10am UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/1 "2020-03-27T10:10:49Z")

</div>

Hi, I created this topic for those who have questions and worries concerning this Gsoc project idea. I have alot of worries. I hope it helps us all.

---

<div class="post-metadata">

**Author:** ![mksd](https://talk.openmrs.org/user_avatar/talk.openmrs.org/mksd/32/11729_2.png) [@mksd](https://talk.openmrs.org/u/mksd)\
**Post date:** [March 27, 2020, 10:29am UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/2 "2020-03-27T10:29:05Z")

</div>

Hi @joachimjunior, I keep seeing the “OAuth2 module” popping up in conversations, but what does it do?

In particular how does it compare to [OAuth 2 Login](https://github.com/openmrs/openmrs-module-oauth2login)?

@dkayiwa, do you know?

---

<div class="post-metadata">

**Author:** ![sidvaish97](https://talk.openmrs.org/user_avatar/talk.openmrs.org/sidvaish97/32/19702_2.png) [@sidvaish97](https://talk.openmrs.org/u/sidvaish97)\
**Post date:** [March 27, 2020, 10:36am UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/3 "2020-03-27T10:36:25Z")

</div>

@mksd I have some idea on this. So the OAuth2 module is for protecting the FHIR resources and exposing it to the SMART Apps after authorisation through the OAuth2 authorisation server.

---

<div class="post-metadata">

**Author:** ![dkayiwa](https://talk.openmrs.org/user_avatar/talk.openmrs.org/dkayiwa/32/179_2.png) [@dkayiwa](https://talk.openmrs.org/u/dkayiwa)\
**Post date:** [March 27, 2020, 10:39am UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/4 "2020-03-27T10:39:16Z")

</div>

[https://wiki.openmrs.org/display/projects/Advancement+of+OAuth2+Module+and+Improvements+in+SMART+OWA](https://wiki.openmrs.org/display/projects/Advancement+of+OAuth2+Module+and+Improvements+in+SMART+OWA)

---

<div class="post-metadata">

**Author:** ![mksd](https://talk.openmrs.org/user_avatar/talk.openmrs.org/mksd/32/11729_2.png) [@mksd](https://talk.openmrs.org/u/mksd)\
**Post date:** [March 27, 2020, 10:39am UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/5 "2020-03-27T10:39:22Z")

</div>

Thanks @sidvaish97.

And why not shielding _all_ accesses to OpenMRS like OAuth 2 Login does?

Was there a need to segregate the invocations of FHIR resources from other application accesses?

@ibacher, would you know?

---

<div class="post-metadata">

**Author:** ![sidvaish97](https://talk.openmrs.org/user_avatar/talk.openmrs.org/sidvaish97/32/19702_2.png) [@sidvaish97](https://talk.openmrs.org/u/sidvaish97)\
**Post date:** [March 27, 2020, 10:42am UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/6 "2020-03-27T10:42:26Z")

</div>

@mksd Yes so for the SMART Apps to be able to access the OpenMRS data its a requirement to have OAuth2 protecting the FHIR resources

Its a sort of standard for all EMR’s to have if they want the SMART Apps to be able to Plug and Play

---

<div class="post-metadata">

**Author:** ![mksd](https://talk.openmrs.org/user_avatar/talk.openmrs.org/mksd/32/11729_2.png) [@mksd](https://talk.openmrs.org/u/mksd)\
**Post date:** [March 27, 2020, 10:47am UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/7 "2020-03-27T10:47:38Z")

</div>

What I’m saying is that OAuth 2 Login protects **all** resources, FHIR or not FHIR.

It currently supports [multiple scopes](https://github.com/openmrs/openmrs-module-oauth2login/blob/65868c1a7c7cd08bd89dec0041e001dd62c11e7f/omod/src/main/java/org/openmrs/module/oauth2login/web/controller/OAuth2BeanFactory.java#L83) (as seen [here](https://github.com/openmrs/openmrs-module-oauth2login/blob/65868c1a7c7cd08bd89dec0041e001dd62c11e7f/omod/src/test/resources/GoogleAPI/oauth2.properties#L15) for example) and [runs against Spring Security 2.3.5.RELEASE](https://github.com/openmrs/openmrs-module-oauth2login/blob/65868c1a7c7cd08bd89dec0041e001dd62c11e7f/pom.xml#L33).

---

<div class="post-metadata">

**Author:** ![sidvaish97](https://talk.openmrs.org/user_avatar/talk.openmrs.org/sidvaish97/32/19702_2.png) [@sidvaish97](https://talk.openmrs.org/u/sidvaish97)\
**Post date:** [March 27, 2020, 10:51am UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/8 "2020-03-27T10:51:52Z")

</div>

Maybe @ibacher can explain this better.

---

<div class="post-metadata">

**Author:** ![joachimjunior](https://talk.openmrs.org/user_avatar/talk.openmrs.org/joachimjunior/32/14667_2.png) [@joachimjunior](https://talk.openmrs.org/u/joachimjunior)\
**Post date:** [March 27, 2020, 12:19pm UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/9 "2020-03-27T12:19:36Z")

</div>

Hi @mskd, I think @sidvaish97 has said what i had in mind.

May @ibacher will help us with clarifications.

---

<div class="post-metadata">

**Author:** ![joachimjunior](https://talk.openmrs.org/user_avatar/talk.openmrs.org/joachimjunior/32/14667_2.png) [@joachimjunior](https://talk.openmrs.org/u/joachimjunior)\
**Post date:** [March 27, 2020, 12:24pm UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/10 "2020-03-27T12:24:54Z")

</div>

For the OATH2 module, i think it works alright. But the task ahead is is to upgrade the version to Spring Security OAuth2 2.x ensuring that the module works fine against latest OpenMRS release because currently the OAuth2 module works on Spring Security OAuth2 version 1.0.5.

I hope this helps 🙂 !

---

<div class="post-metadata">

**Author:** ![ibacher](https://talk.openmrs.org/user_avatar/talk.openmrs.org/ibacher/32/19751_2.png) [@ibacher](https://talk.openmrs.org/u/ibacher)\
**Post date:** [March 27, 2020, 2:17pm UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/11 "2020-03-27T14:17:32Z")

</div>

> [@mksd](#):
>
> @ibacher, would you know?

So, my idea here is to have a soft touch with what we are doing. It should be extensible enough to use OAuth2 to shield all accesses to OpenMRS resources (I mean, this is just a matter of changing the URL configuration).

There are also slightly different goals, I think. OAuth2 login, as I understand it, is for providing login using, e.g., Google or whatever instead of having OpenMRS responsible for authentication. With this project we’re actually trying to make OpenMRS act as an OAuth2 server (again, primarily so we can utilise SMART on FHIR in a single-server setup).

Does that clarify things a bit?

---

<div class="post-metadata">

**Author:** ![ibacher](https://talk.openmrs.org/user_avatar/talk.openmrs.org/ibacher/32/19751_2.png) [@ibacher](https://talk.openmrs.org/u/ibacher)\
**Post date:** [March 27, 2020, 2:18pm UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/12 "2020-03-27T14:18:48Z")

</div>

In other words, what we’re doing is somewhat orthogonal to to the OAuth2 login module.

---

<div class="post-metadata">

**Author:** ![mksd](https://talk.openmrs.org/user_avatar/talk.openmrs.org/mksd/32/11729_2.png) [@mksd](https://talk.openmrs.org/u/mksd)\
**Post date:** [March 27, 2020, 2:26pm UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/13 "2020-03-27T14:26:02Z")

</div>

Yes, if this module turns OpenMRS into an authentication _provider_, then it’s definitely a very different ball game. But I think the naming should reflect that. It should literally be named ‘OAuth 2 Server’ or something.

Why do that tho, is it because in this SMART setup OpenMRS (so the EMR) is supposedly where users are maintained and where roles are assigned to users?

On the other hand when it comes to systems integration, one should assume that there is already a centralised place where users are managed and roles are assigned (an Active Directory typically, or equivalent.)

---

<div class="post-metadata">

**Author:** ![ibacher](https://talk.openmrs.org/user_avatar/talk.openmrs.org/ibacher/32/19751_2.png) [@ibacher](https://talk.openmrs.org/u/ibacher)\
**Post date:** [March 27, 2020, 2:35pm UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/14 "2020-03-27T14:35:35Z")

</div>

> [@mksd](#):
>
> Yes, if this module turns OpenMRS into an authentication _provider_ , then it’s definitely a very different ball game. But I think the naming should reflect that. It should literally be named ‘OAuth 2 Server’ or something.

You’re probably right about that; I didn’t name the module. In fact, given a choice, I’d probably call it “openmrs-module-smart”, because all of the OAuth2 stuff is really just incidental to being able to support SMART.

> [@mksd](#):
>
> Why do that tho, is it because in this SMART setup OpenMRS (so the EMR) is supposedly where users are maintained and where roles are assigned to users?

Yes, in as much as that’s the default configuration of OpenMRS and the pattern that used for many installations. It’s not my ideal state of things, however; I’d really prefer to have authentication handled by something like [Keycloak](https://www.keycloak.org/) or another OAuth2 provider, but my first target is to ensure we can launch SMART apps from within OpenMRS and this is the path of least resistance.

> [@mksd](#):
>
> On the other hand when it comes to systems integration, one should assume that there is already a centralised place where users are managed and roles are assigned (an Active Directory typically, or equivalent.)

Indeed, I’d hope that was the case!

---

<div class="post-metadata">

**Author:** ![mksd](https://talk.openmrs.org/user_avatar/talk.openmrs.org/mksd/32/11729_2.png) [@mksd](https://talk.openmrs.org/u/mksd)\
**Post date:** [March 27, 2020, 2:44pm UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/15 "2020-03-27T14:44:07Z")

</div>

Why not using this module alongside OAuth 2 Login configured for Keycloak? Isn’t that getting you closer to the real end game?

---

<div class="post-metadata">

**Author:** ![ibacher](https://talk.openmrs.org/user_avatar/talk.openmrs.org/ibacher/32/19751_2.png) [@ibacher](https://talk.openmrs.org/u/ibacher)\
**Post date:** [March 27, 2020, 3:03pm UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/16 "2020-03-27T15:03:38Z")

</div>

If this was completely new work, that would be the approach, but this is [building on an already existing module](https://github.com/openmrs/openmrs-module-oauth2). The real focus for this GSoC project is:

1. Integrating the SMART on FHIR components with the FHIR2 module.
2. Providing a better experience for registering and maintaining SMART applications.
3. Providing a way to integrate SMART applications into the OpenMRS UI

Getting bogged down in setting up and configuring Keycloak or another provider distracts from those goals.

---

<div class="post-metadata">

**Author:** ![prapakaran](https://talk.openmrs.org/letter_avatar/prapakaran/32/5_5575768a8748004e209b776fc1b2916d.png) [@prapakaran](https://talk.openmrs.org/u/prapakaran)\
**Post date:** [April 3, 2020, 3:58pm UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/17 "2020-04-03T15:58:41Z")

</div>

@ibacher Is it possible add scope for social media ids(facebook, gmail, twitter) to login the OpenMRS system. Hopefully SMART supports for this functionality as well. It helps health works no need remember separate password and also openMRS no need to maintain passwords.

---

<div class="post-metadata">

**Author:** ![ibacher](https://talk.openmrs.org/user_avatar/talk.openmrs.org/ibacher/32/19751_2.png) [@ibacher](https://talk.openmrs.org/u/ibacher)\
**Post date:** [April 3, 2020, 5:30pm UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/18 "2020-04-03T17:30:10Z")

</div>

That’s definitely outside of the scope of this project; however, the [OAuth2Login](https://github.com/openmrs/openmrs-module-oauth2login) mentioned by @mksd above already exists and supports this functionality, so I’d have a look at that.

---

<div class="post-metadata">

**Author:** ![ayesh](https://talk.openmrs.org/user_avatar/talk.openmrs.org/ayesh/32/10674_2.png) [@ayesh](https://talk.openmrs.org/u/ayesh)\
**Post date:** [April 5, 2020, 4:39pm UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/19 "2020-04-05T16:39:34Z")

</div>

@ibacher Oh its great to see we have keycloack. It’s already an Oauth server which can handle all oauth flows.

I think we can possibly use client secret auth flow which is provided by keycloack to expose fhir resources to SMART apps?.

Btw is oauth 2 login app mentioned @mksd does it works as a middle layer for keycloack?

How does it works all the users stored in openmrs user db stored in keycloack as well ?

---

<div class="post-metadata">

**Author:** ![mksd](https://talk.openmrs.org/user_avatar/talk.openmrs.org/mksd/32/11729_2.png) [@mksd](https://talk.openmrs.org/u/mksd)\
**Post date:** [April 6, 2020, 8:02am UTC](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651/20 "2020-04-06T08:02:32Z")

</div>

> [@ayesh](#):
>
> Btw is oauth 2 login app mentioned @mksd does it works as a middle layer for keycloack?

There’s a pretty [exhaustive README](https://github.com/openmrs/openmrs-module-oauth2login/blob/master/README.md) for that module, did you go through it? There’s also [configuration guides](https://github.com/openmrs/openmrs-module-oauth2login/blob/master/README.md#configuration-guides) to make it work with Google API and Keycloak.

I’m not sure what you mean by “middle layer” in this context. Keycloak is an authentication provider, if you decide to use OpenMRS with it, then OpenMRS must become a Keycloak _client_ and should stop owning and performing the authentication process. **‘OAuth 2 Login’ turns OpenMRS into a client that authenticates with a provider over OAuth 2**.

> [@ayesh](#):
>
> How does it works all the users stored in openmrs user db stored in keycloack as well ?

Yes, and there is no choice because OpenMRS does not fully support Spring Security.

[Next page](https://talk.openmrs.org/t/gsoc-2020-advancement-of-oauth2-module-and-improvements-in-smart-owa/27651.md?page=2)
