Skip to main content

Backend API

What it does​

RxDrugIntent-MP-Core is the core backend API service for CLIC — the Clinical List Intent and Configuration API. It exposes the operations that back drug intent creation, updates, and search, and is the system of record that DrugIntentBFF calls on behalf of the UI.

Per the project's architecture overview, the "Core Service" role is to orchestrate the overall workflow and coordinate calls to other services — it's the hub the BFF delegates business logic to, rather than a thin CRUD layer. See BFF Layer for how the surrounding microservice layer (Formulary Service, Maintenance/Timer Service, Downstream Push Services) fits together; it is not yet confirmed which of those are part of this repo versus separate deployables.

How it works​

The service is a Java API (Maven build, .iml project) — no further internal design detail is available in the collected README. It relies on RxDrugIntentDataModelLib for its DTOs, entities, and enums (shared with other Drug Intent services).

Security​

  • Auth: AuthPass OAuth 2.0 / JWT bearer (RFC 6750), 15-minute token TTL with refresh
  • Authorization: owner-only modification on drug-intent records; Admin has a separate, read-only administration API path
  • Secrets: environment variables via a managed secret store — no secrets in code
  • Client credential rotation: 90-day expiry with 15-day advance notification

Non-functional targets​

RequirementTarget
API latencyP95 < 150ms
Availability99.9% monthly
Rate limit100 req/min per IP

Observability​

  • Structured JSON logs (level, userId, requestId, endpoint, latency, outcome — PII redacted)
  • Metrics: API latency (p50/p95/p99), error rate, upload success rate
  • Distributed tracing via OpenTelemetry/Splunk

Known gaps / open questions​

  • Only a two-line README was collected — no concrete endpoint list exists for this repo specifically. The LLD documents a /api/v1/drug-intent REST surface at the product level, but that is currently attributed to the BFF (the UI-facing service) rather than confirmed as Core's own contract — see BFF Layer.
  • Whether "Formulary Service", "Maintenance/Timer Service", and "Downstream Push Services" (named in the project's microservice-layer table) are modules inside this repo or separate services is not documented.
  • Relationship to DrugIntentBFF (which endpoints it calls, request/response shapes) is not yet documented.

Technical reference​

DetailValue
RepoRxDrugIntent-MP-Core
BuildMaven (pom.xml)
Shared modelRxDrugIntentDataModelLib
AuthAuthPass OAuth 2.0 / JWT bearer
Rate limit100 req/min per IP