Backend API
What it does
RxDrugIntent-MP-Core is the core backend API service for CLIC — the Clinical List Intent and Configuration API. It exposes the operations that back drug intent creation, updates, and search, and is the system of record that DrugIntentBFF calls on behalf of the UI.
Per the project's architecture overview, the "Core Service" role is to orchestrate the overall workflow and coordinate calls to other services — it's the hub the BFF delegates business logic to, rather than a thin CRUD layer. See BFF Layer for how the surrounding microservice layer (Formulary Service, Maintenance/Timer Service, Downstream Push Services) fits together; it is not yet confirmed which of those are part of this repo versus separate deployables.
How it works
The service is a Java API (Maven build, .iml project) — no further internal design detail is available in the collected README. It relies on RxDrugIntentDataModelLib for its DTOs, entities, and enums (shared with other Drug Intent services).
Security
- Auth: AuthPass OAuth 2.0 / JWT bearer (RFC 6750), 15-minute token TTL with refresh
- Authorization: owner-only modification on drug-intent records; Admin has a separate, read-only administration API path
- Secrets: environment variables via a managed secret store — no secrets in code
- Client credential rotation: 90-day expiry with 15-day advance notification
Non-functional targets
| Requirement | Target |
|---|---|
| API latency | P95 < 150ms |
| Availability | 99.9% monthly |
| Rate limit | 100 req/min per IP |
Observability
- Structured JSON logs (level, userId, requestId, endpoint, latency, outcome — PII redacted)
- Metrics: API latency (p50/p95/p99), error rate, upload success rate
- Distributed tracing via OpenTelemetry/Splunk
Known gaps / open questions
- Only a two-line README was collected — no concrete endpoint list exists for this repo specifically. The LLD documents a
/api/v1/drug-intentREST surface at the product level, but that is currently attributed to the BFF (the UI-facing service) rather than confirmed as Core's own contract — see BFF Layer. - Whether "Formulary Service", "Maintenance/Timer Service", and "Downstream Push Services" (named in the project's microservice-layer table) are modules inside this repo or separate services is not documented.
- Relationship to
DrugIntentBFF(which endpoints it calls, request/response shapes) is not yet documented.
Technical reference
| Detail | Value |
|---|---|
| Repo | RxDrugIntent-MP-Core |
| Build | Maven (pom.xml) |
| Shared model | RxDrugIntentDataModelLib |
| Auth | AuthPass OAuth 2.0 / JWT bearer |
| Rate limit | 100 req/min per IP |