fhir_r6_auth 0.12.0
fhir_r6_auth: ^0.12.0 copied to clipboard
Secure authentication and authorization package for FHIR R6 applications implementing SMART on FHIR
fhir_r6_auth #
0.12.0 #
- No code changes; version aligned with the fhir_r4 0.12.0 family release
0.9.0 #
- No code changes; version aligned with the fhir_r6 0.9.0 family release
0.8.0 #
- No code changes; version aligned with the fhir_r6 0.8.0 family release
0.7.3 #
Robustness hardening (library code only; fhir_r6 core unchanged at ^0.7.0):
- All OAuth/OpenID Connect HTTP calls (token exchange, refresh, client-credentials grant, revocation, SMART discovery, JWKS fetch, token introspection) now enforce a 30-second network timeout (configurable via
networkTimeout), so a hung or slow server can no longer block the auth flow indefinitely. JwtValidatornow releases the HTTP client it owns viadispose(), andOAuthFlow.dispose()disposes the validator it created — fixing a socket leak on JWKS-verifying flows.- Example updated to demonstrate the
allowedIssuersallowlist for EHR launches.
0.7.2 #
Second security hardening pass (library code only; fhir_r6 core unchanged at ^0.7.0):
- Fixed a broken concurrency guard where the "prevent concurrent refreshes" lock was permanently completed and did nothing — parallel refreshes are now coalesced into a single token exchange. This prevents refresh-token-rotation servers from rejecting a racing refresh and invalidating the token family.
- Refresh no longer discards the refresh token when the server omits it from a refresh response (RFC 6749 §6) — the existing refresh token is carried forward instead of being nulled out.
- TLS is now enforced on the SMART discovery documents (
.well-known/smart-configurationand/metadata) and on the token introspection endpoint, closing the remaining plaintext paths (loopback still allowed;allowInsecureConnectionsopt-out). - The bearer token is now origin-bound: it is attached only to requests whose scheme/host/port match the configured FHIR server, so it cannot leak to another host.
SmartConfig.fromLaunchParametersaccepts anallowedIssuersset and rejects an EHR-launchissthat is not allowlisted (mitigates SMART "iss spoofing" token theft).- JWT verification enforces an algorithm allowlist (rejects
alg: noneand unknown algorithms) and rejects tokens carrying their own key material or key references (jwk/jku/x5u/x5c). - Client-assertion JWTs (
createSignedJwt) now use a random UUIDjtiinstead of a timestamp. - PKCE can no longer be disabled for a public SMART client.
at_hash, nonce, and PKCE challenge comparisons now use a constant-time equality check.
0.7.1 #
Security hardening of the SMART on FHIR auth flow (auth-only patch; fhir_r6 core unchanged at ^0.7.0):
- id_token validation now fails closed:
JwtValidator.validateTokenverifies the signature against the server's JWKS (discovered from.well-known/smart-configuration) and pins the expected issuer and audience (audience defaults to the client_id). When no key material is available it throws instead of silently decoding — passallowUnverified: true(or usedecodeWithoutValidation) for the previous behavior.OAuthFlowgainedjwksUri/expectedIssuer/expectedAudience. - Session timeout now purges the in-memory tokens: on idle/absolute timeout the client immediately stops attaching the bearer token (previously the timeout only cleared persistent storage, so the cached token kept being sent). New
FhirAuthClient.clearInMemoryTokens(). - HTTPS is now enforced on all OAuth/OpenID Connect endpoints (authorization, token, revocation, and JWKS). Non-HTTPS URLs throw
SecurityException; loopback hosts remain allowed for local development, andallowInsecureConnections(onAuthConfig/OAuthFlow/JwtValidator) is an explicit opt-out. - iOS keychain items now use
first_unlock_this_device, keeping credentials on-device (excluded from iCloud Keychain sync and cross-device backup restore). AuthConfig.toJson()no longer serializes secrets (clientSecret,BackendServiceConfig.privateKey) by default — passincludeSecrets: trueto persist them deliberately.- jose remains ^0.3.5+2 (GHSA-vm9r-h74p-hg97 / CVE-2026-34240 patched)
0.7.0 #
- Family release train: cores and companions released in lockstep at 0.7.0
- README: SMART App Launch link now https
- Tests: replaced a statistically unsound PKCE repeated-pattern test (CI flake)
- fhir_r6 ^0.7.0
0.6.0 #
- flutter_appauth ^12.0.0 + flutter_web_auth_2 ^5.0.0 (verified live against the Epic sandbox: standalone patient+clinician on web, EHR launch on web, standalone on Linux desktop)
- Fixed desktop (Linux/Windows) sign-in being cancelled when the app window regained focus mid-login: the plugin's app-resume cleanup force-closed its local callback server; the authenticator now invokes the desktop platform implementation directly
- Security: jose bumped to ^0.3.5+2 (GHSA-vm9r-h74p-hg97 / CVE-2026-34240, JWS signature-verification bypass)
- Removed the unused dart_jsonwebtoken dependency
- Family lockstep 0.6.0; runnable example added; README rewritten and verified against the API (login/refreshToken); package-local lint relaxations removed, analyzer clean
0.5.1 #
- Improved documentation and README files
0.5.0 #
- Unified versioning across all fhir_r6 packages
- Updated dependencies
- Initial publication to pub.dev