# OpenMRS ID Platform Improvements Midterm Presentation

**URL:** https://talk.openmrs.org/t/openmrs-id-platform-improvements-midterm-presentation/321
**Category:** GSoC
**Tags:** gsoc2014
**Created:** [June 22, 2014, 6:27pm UTC](https://talk.openmrs.org/t/openmrs-id-platform-improvements-midterm-presentation/321 "2014-06-22T18:27:03Z")
**Posts on this page:** 1
**Showing post:** 4

<div class="post-metadata">

### Author: ![plypy](https://talk.openmrs.org/user_avatar/talk.openmrs.org/plypy/32/505_2.png) [@plypy](https://talk.openmrs.org/u/plypy)
#### Post date: [June 24, 2014, 4:46pm UTC](https://talk.openmrs.org/t/openmrs-id-platform-improvements-midterm-presentation/321/4 "2014-06-24T16:46:46Z")

</div>

Yah, Dashboard 2.0 will come soon 😄

Questions

> [@burke](#):
>
> How will clients of the API authenticate to it – i.e., who or what will have access to modify a user’s record?

It’s not decided yet, maybe use http authenticate. And @elliott suggested we can use OAuth to restrict the privileges of Clients. You can see this [discussion](https://talk.openmrs.org/t/api-data-model-design-discussion-free-form-data/282)

> [@burke](#):
>
> If you have authority to make changes to the user’s entry, will you be on the honor code – i.e., clients are expected to only make changes to their own settings, but could technically change anything? Or will there be some scoping of authority so, for example, Atlas could only make changes to properties within extras.atlas?

Basically yes, I think, a client could only editing its own data. Each Client will only know its own existence. Maybe they can read others data? I’m not sure for this. But it seems to be a bad idea.

> [@burke](#):
>
> Do you have thoughts on how you would control the namespace? For example, what if two different projects want to use extras.foobar.\*?

Though, we don’t have much client… the chance of duplicating is there. So I’ll make sure each scope has a unique identifier, by setting unique indexes. And maybe auto generate unique identifiers.

Things related with RESTful API is still in discussion and design, and I havn’t done any tests. Thus, things may change.

---

_[View the full topic](https://talk.openmrs.org/t/openmrs-id-platform-improvements-midterm-presentation/321)._
