Specification
Service logic
- Only authenticated and authorized user can use patient request
- Service returns only patient request related to the same legal entity as the user
Authentication
- Verify the validity of access token
- Return 401 in case validation fails
- Check scopes in order to perform this action (scope = 'patient_request:read')
- Return 403 in case invalid scope(s)
Confidant person
In block confidant person, don't show id. Show - last_name, first_name, birth_date?
Auth_methods
If type= third_person` and in field `
value` instead ID show
confidant_person.auth_method.value