1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
//! Permission
//!
//! URL: http://hl7.org/fhir/StructureDefinition/Permission
//!
//! Version: 5.0.0
//!
//! Permission Resource: Permission resource holds access rules for a given data and context.
//!
//! FHIR: <https://build.fhir.org/>
//!
//! UML: <https://build.fhir.org/uml.html>
// Allow unused crate::r5::types as types;
#![allow(unused_imports)]
use crate::r5::types;
use ::serde::{Deserialize, Serialize};
use fhir_derive_macros::Validate;
/// The Permission resource holds access rules for a given data and context.
///
/// In FHIR R5 the Permission resource captures a machine-processable authorization
/// policy: it expresses the set of constraints under which specific data may be
/// accessed or acted upon. Each Permission carries one or more rules that either
/// permit or deny particular activities, scoped by the actors involved, the
/// purposes of use, the actions performed, and the data selected by explicit
/// references, security labels, time periods, or FHIRPath expressions. A Permission
/// is asserted by a person or organization, may be constrained to a validity
/// period, and specifies a combining algorithm (for example deny-overrides or
/// permit-overrides) that determines how its rules are reconciled when more than
/// one applies. This makes it well suited to modeling fine-grained access-control
/// decisions, security policies, and the enforceable representation of a patient's
/// or organization's data-sharing directives.
///
/// # Related resources
///
/// A Permission frequently complements a broader
/// [`Consent`](crate::r5::resources::consent::Consent), which records a subject's
/// wishes, while the Permission expresses the enforceable rules derived from them.
/// Rules commonly reference actors and data such as
/// [`Patient`](crate::r5::resources::patient::Patient) records and audit trails
/// like [`Provenance`](crate::r5::resources::provenance::Provenance), and they
/// classify activities and limits using
/// [`CodeableConcept`](crate::r5::types::CodeableConcept) values.
///
/// # Examples
///
/// ```
/// use fhir::r5::resources::permission::Permission;
///
/// let value = Permission::default();
/// let json = ::serde_json::to_value(&value).unwrap();
/// let back: Permission = ::serde_json::from_value(json).unwrap();
/// assert_eq!(value, back);
/// ```
#[serde_with::skip_serializing_none]
#[derive(Debug, Default, Clone, Serialize, Deserialize, PartialEq, Eq, Validate)]
#[serde(rename_all = "camelCase")]
pub struct Permission {
/// Logical id of this artifact
pub id: Option<types::String>,
/// Metadata about the resource
pub meta: Option<types::Meta>,
/// A set of rules under which this content was created
pub implicit_rules: Option<types::Uri>,
/// Primitive extension sibling for [`implicit_rules`](Self::implicit_rules) (FHIR `_implicitRules`).
#[serde(rename = "_implicitRules")]
pub implicit_rules_ext: Option<types::Element>,
/// Language of the resource content
pub language: Option<types::Code>,
/// Primitive extension sibling for [`language`](Self::language) (FHIR `_language`).
#[serde(rename = "_language")]
pub language_ext: Option<types::Element>,
/// Text summary of the resource, for human interpretation
pub text: Option<types::Narrative>,
/// Contained, inline Resources
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub contained: Vec<::serde_json::Value>,
/// Additional content defined by implementations
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub extension: Vec<types::Extension>,
/// Extensions that cannot be ignored
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub modifier_extension: Vec<types::Extension>,
/// Lifecycle state of the permission: active, entered-in-error, draft, or rejected.
pub status: crate::r5::coded::Coded<crate::r5::codes::PermissionStatus>,
/// Primitive extension sibling for [`status`](Self::status) (FHIR `_status`).
#[serde(rename = "_status")]
pub status_ext: Option<types::Element>,
/// Reference to the person or entity that asserts this permission and its rules.
pub asserter: Option<types::Reference>,
/// The date(s) on which the permission was asserted by the asserter.
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub date: Vec<types::DateTime>,
/// Primitive extension sibling for [`date`](Self::date) (FHIR `_date`).
#[serde(rename = "_date")]
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub date_ext: Vec<Option<types::Element>>,
/// The period during which this permission's rules are in effect.
pub validity: Option<types::Period>,
/// The legal or regulatory basis and supporting evidence justifying the use of the data.
pub justification: Option<PermissionJustification>,
/// Combining algorithm that reconciles conflicting rules: deny-overrides, permit-overrides, ordered-deny-overrides, ordered-permit-overrides, deny-unless-permit, or permit-unless-deny.
pub combining: crate::r5::coded::Coded<crate::r5::codes::PermissionRuleCombining>,
/// Primitive extension sibling for [`combining`](Self::combining) (FHIR `_combining`).
#[serde(rename = "_combining")]
pub combining_ext: Option<types::Element>,
/// The ordered set of rules that constrain access under this permission.
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub rule: Vec<PermissionRule>,
}
/// The asserted justification for using the data.
#[serde_with::skip_serializing_none]
#[derive(Debug, Default, Clone, Serialize, Deserialize, PartialEq, Eq, Validate)]
#[serde(rename_all = "camelCase")]
pub struct PermissionJustification {
/// Unique id for inter-element referencing
pub id: Option<types::String>,
/// Additional content defined by implementations
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub extension: Vec<types::Extension>,
/// Extensions that cannot be ignored even if unrecognized
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub modifier_extension: Vec<types::Extension>,
/// The regulatory grounds upon which this Permission builds
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub basis: Vec<types::CodeableConcept>,
/// Justifing rational
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub evidence: Vec<types::Reference>,
}
/// Constraints to the Permission.
#[serde_with::skip_serializing_none]
#[derive(Debug, Default, Clone, Serialize, Deserialize, PartialEq, Eq, Validate)]
#[serde(rename_all = "camelCase")]
pub struct PermissionRule {
/// Unique id for inter-element referencing
pub id: Option<types::String>,
/// Additional content defined by implementations
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub extension: Vec<types::Extension>,
/// Extensions that cannot be ignored even if unrecognized
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub modifier_extension: Vec<types::Extension>,
/// deny | permit
pub r#type: Option<crate::r5::coded::Coded<crate::r5::codes::ConsentProvisionType>>,
/// Primitive extension sibling for [`type`](Self::r#type) (FHIR `_type`).
#[serde(rename = "_type")]
pub type_ext: Option<types::Element>,
/// The selection criteria to identify data that is within scope of this provision
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub data: Vec<PermissionRuleData>,
/// A description or definition of which activities are allowed to be done on the data
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub activity: Vec<PermissionRuleActivity>,
/// What limits apply to the use of the data
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub limit: Vec<types::CodeableConcept>,
}
/// The selection criteria to identify data that is within scope of this provision.
#[serde_with::skip_serializing_none]
#[derive(Debug, Default, Clone, Serialize, Deserialize, PartialEq, Eq, Validate)]
#[serde(rename_all = "camelCase")]
pub struct PermissionRuleData {
/// Unique id for inter-element referencing
pub id: Option<types::String>,
/// Additional content defined by implementations
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub extension: Vec<types::Extension>,
/// Extensions that cannot be ignored even if unrecognized
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub modifier_extension: Vec<types::Extension>,
/// Explicit FHIR Resource references
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub resource: Vec<PermissionRuleDataResource>,
/// Security tag code on .meta.security
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub security: Vec<types::Coding>,
/// Timeframe encompasing data create/update
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub period: Vec<types::Period>,
/// Expression identifying the data
pub expression: Option<types::Expression>,
}
/// Explicit FHIR Resource references.
#[serde_with::skip_serializing_none]
#[derive(Debug, Default, Clone, Serialize, Deserialize, PartialEq, Eq, Validate)]
#[serde(rename_all = "camelCase")]
pub struct PermissionRuleDataResource {
/// Unique id for inter-element referencing
pub id: Option<types::String>,
/// Additional content defined by implementations
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub extension: Vec<types::Extension>,
/// Extensions that cannot be ignored even if unrecognized
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub modifier_extension: Vec<types::Extension>,
/// instance | related | dependents | authoredby
pub meaning: crate::r5::coded::Coded<crate::r5::codes::ConsentDataMeaning>,
/// Primitive extension sibling for [`meaning`](Self::meaning) (FHIR `_meaning`).
#[serde(rename = "_meaning")]
pub meaning_ext: Option<types::Element>,
/// The actual data reference
pub reference: types::Reference,
}
/// A description or definition of which activities are allowed to be done on the data.
#[serde_with::skip_serializing_none]
#[derive(Debug, Default, Clone, Serialize, Deserialize, PartialEq, Eq, Validate)]
#[serde(rename_all = "camelCase")]
pub struct PermissionRuleActivity {
/// Unique id for inter-element referencing
pub id: Option<types::String>,
/// Additional content defined by implementations
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub extension: Vec<types::Extension>,
/// Extensions that cannot be ignored even if unrecognized
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub modifier_extension: Vec<types::Extension>,
/// Authorized actor(s)
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub actor: Vec<types::Reference>,
/// Actions controlled by this rule
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub action: Vec<types::CodeableConcept>,
/// The purpose for which the permission is given
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub purpose: Vec<types::CodeableConcept>,
}
#[cfg(test)]
mod tests {
use super::*;
type T = Permission;
#[test]
fn test_default() {
let _ = T::default();
}
#[test]
fn test_serde_round_trip() {
let value = T::default();
let json = ::serde_json::to_value(&value).expect("to_value");
let back: T = ::serde_json::from_value(json).expect("from_value");
assert_eq!(value, back);
}
}