ЕСОЗ - публічна документація
REST API Reject Medication Request by Pharmacy User [API-005-008-002-0150]
- 1 Properties of a REST API method document
- 2 Purpose
- 2.1 Key points
- 3 Logic
- 3.1 Service logic
- 4 Configuration parameters
- 5 Dictionaries
- 6 Input parameters
- 7 Request structure
- 8 Headers
- 9 Request data validation
- 9.1 Authorization
- 9.2 Validations
- 9.2.1 Validate Digital Sign
- 9.2.2 Validate Medication request
- 9.2.3 Validate user
- 9.2.4 Validate content
- 9.2.5 Validation transition
- 9.2.6 Validate reject reason code
- 9.2.7 Validate reject reason
- 10 Processing
- 11 Response structure examples
- 12 HTTP status codes
- 13 Post-processing processes
- 14 Technical modules where the method is used
Properties of a REST API method document
Document type | Метод REST API |
Document title | REST Reject Medication Request by Pharmacy User [API-005-008-002-0150] |
Guideline ID | GUI-0011 |
Author | @Iryna Lishtaba (SoE eHealth) |
Document version | 1 |
Document status | PROD |
Date of creation | 03.03.2025 |
Date of update | 03.03.2025 |
Method API ID | API-005-008-002-0150 |
Microservices (namespace) | IL |
Link на API-специфікацію | |
Resource | {{host}}/api/pharmacy/medication_requests/{{id}}/actions/reject |
Scope | medication_request:reject_pharm |
Protocol type | REST |
Request type | PATCH |
Sync/Async | Sync |
Public/Private | Public |
This WS is designed to Reject Medication Request by Pharmacy users.
Key points
Only authenticated and authorized user with appropriate scope can reject Medication Request.
In request in signed content the Medication Request data should be used the same as in response of Get Medication Request by Pharmacy User.
In the response of this endpoint legal entity, division and employee details are trimmed, according to business requirements (limitations) for Pharmacy.
Medication Request can be rejected only from ‘ACTIVE' status.
Service logic
Save signed content to media storage.
Update Medication request in OPS DB:
set status = 'REJECTED'
set reject_reason_code = $.reject_reason_code
set reject_reason = $.reject_reason
set updated_by = user_id
set updated_at = now()
set rejected_by = user_id
set rejected_at = now()
Send SMS for person
If Medication request has program with medical program setting request_notification_disabled = true, then don't send SMS.
Get authentication_method of person from MPI
If authentication_method == OTP, then send SMS to a person from Medication request:
Generate SMS text
get template from reject_template_sms parameter
enrich template with data from Medication request
Send SMS to a person
Render response according to specification
Add new record to Event manager
field | value |
event_type | StatusChangeEvent |
entity_type | MedicationRequest |
entity_id | $.id |
properties.status.new_value | $.status |
event_time | $.update_at |
changed_by | $.changed_by |
if the medication request is based on the activity with quantity:
Recalculate and set remaining_quantity for the activity as described at Create Medication Request: Validate based_on (p. 2.d.1 ) and do not include current MR but include all MD which related to current MR
Configuration parameters
Input parameters
Input parameter | Mandatory | Type | Description | Example | |
1 | id | M | String | Medication Request identifier | a89f6a26-4221-4597-a1d2-542d5e40b565 |
Request structure
See on API-specification
Request data validation
Verify the validity of access token
in case of error - return 401 (“Invalid access token”) in case of validation fails
Verify that token is not expired
in case of error - return 401 (“Invalid access token”)
Check user scopes in order to perform this action (scope = 'medication_request:reject_pharm')
return 403 (“Your scope does not allow to access this resource. Missing allowances: medication_request:reject_pharm”) in case of invalid scope(s)
Validate Digital Sign
Validate request is signed
in case of error - return 400 (“document must be signed by 1 signer but contains 0 signatures”)
Check DS is valid and not expired
Validate that DS belongs to the user
Check that DRFO from DS and party.tax_id matches
in case of error - return 422 (“Does not match the signer drfo“)
Validate Medication request
Get Medication request identifier from the URL. Check Medication request exists in OPS DB
in case of error - return 404 (“Medication request does not exist")
Validate user
Medication Request rejection is allowed for user if he has active and approved employee
in case of error - return 409 ("Only active and approved employee can reject medication request")
Validate content
Validate request using JSON schema
in case of error - return 422 with appropriate validation error
Check that signed content contains all required fields and is equal to stored object
Decode signed content
Render requested medication request using https://e-health-ua.atlassian.net/wiki/x/6oBMFwQ
Check that rendered and decoded data matches (except for reject_reason_code and reject_reason fields)
in case of error - return 422 ("Signed content does not match the previously created content")
Validation transition
Get status of Medication request by $.id in OPS DB. Check that Medication request is in status ‘ACTIVE’
if invalid - return 409 ("Invalid status Medication request for reject transition!")
For more information look at https://e-health-ua.atlassian.net/wiki/x/YwAUUAQ
Validate reject reason code
Validate $.reject_reason_code is a value from MEDICATION_REQUEST_REJECT_REASON dictionary
in case of error - return 422 ("value is not allowed in enum")
Validate reject reason
Validate $.reject_reason is set in case $.reject_reason_code = 'OTHER'
in case of error - return 422 ("required property reject_reason was not present")
for such case JSON schema for $.reject_reason - minimum 1 symbol
in case of error - return 422 (“expected value to have a minimum length of 1 but was 0”)
Response structure examples
See on API-specification
HTTP status codes
Response code | HTTP Status code | Message | Internal name | Description | |
1 | Базові | ||||
2 |
| 400 | document must be signed by 1 signer but contains 0 signatures |
| На документ має бути накладено 1 цифровий підпис підпис за допомогою КЕП, проте маємо 0 цифрових підписів |
3 |
| 401 | Invalid access token |
| Недійсний токен доступу |
4 |
403 | Your scope does not allow to access this resource. Missing allowances: medication_request:reject_pharm |
| Для вашої ролі відсутній доступ до цього ресурсу. Необхідний доступ працівнику аптеки на скасування рецепта |
5 |
| 404 | Medication request does not exist |
| Електронний рецепт не існує |
6 |
| 409 | Only active and approved employee can reject medication request |
| Лише активний та підтверджений працівник може відхилити електронний рецепт |
7 |
| 409 | Invalid status Medication request for reject transition! |
| Некоректний статус електронного рецепта для його відхилення |
8 | Специфічні | ||||
9 |
| 422 | Does not match the signer drfo |
| РНОКПП користувача не співпадає з РНОКПП, зазначеним у КЕП |
10 |
| 422 | Signed content does not match the previously created content |
| Підписані дані не відповідають раніше створеним |
11 |
| 422 | value is not allowed in enum |
| Недопустиме значення |
12 |
| 422 | required property reject_reason was not present |
| Опис причини скасування електронного рецепту не зазначено |
Post-processing processes
Technical modules where the method is used
Related content
ЕСОЗ - публічна документація