Implement Care Circle Sharing & Delegated Access with granular permissions and audit logging#26
Open
Implement Care Circle Sharing & Delegated Access with granular permissions and audit logging#26
Conversation
Author
|
@hoangsonww 👋 This repository doesn't have Copilot instructions. With Copilot instructions, I can understand the repository better, work faster and produce higher quality PRs. I can generate a .github/copilot-instructions.md file for you automatically. Click here to open a pre-filled issue and assign it to me. I'll write the instructions, and then tag you for review. |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Co-authored-by: hoangsonww <124531104+hoangsonww@users.noreply.github.com>
… API endpoints Co-authored-by: hoangsonww <124531104+hoangsonww@users.noreply.github.com>
…ted access controls Co-authored-by: hoangsonww <124531104+hoangsonww@users.noreply.github.com>
…and examples Co-authored-by: hoangsonww <124531104+hoangsonww@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Care Circle Sharing & Delegated Access (scoped, time-limited)
Implement Care Circle Sharing & Delegated Access with granular permissions and audit logging
Aug 22, 2025
hoangsonww
approved these changes
Sep 9, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR implements a comprehensive Care Circle feature that enables secure, time-limited sharing of health data with trusted caregivers, family members, and clinicians. The implementation provides granular scope-based permissions with complete audit trails and emergency access capabilities.
Key Features
Secure Invitation System
Database Architecture
Four new tables with comprehensive relationships:
care_circle_members- Member relationships and invitation managementaccess_grants- Permission scopes and expiration controlaudit_log- Complete activity tracking with metadataice_tokens- Emergency access code managementEnhanced all existing tables with updated RLS policies supporting delegated access while maintaining security.
API Endpoints
POST /api/care-circle?action=invite- Send secure invitationsGET /api/care-circle- List members with grant detailsPUT /api/care-circle?memberId=X- Update permissions and rolesDELETE /api/care-circle?memberId=X- Revoke access immediatelyGET /api/audit-log- Retrieve filtered activity logs with CSV exportPOST /api/ice- Generate 6-digit emergency access codesUser Interface
Complete Care Circle management interface with:
Security & Compliance
Example Usage
Integration with Existing Features
All existing SymptomSync pages now support delegated access:
The implementation uses
RestrictedAccessWrappercomponents to seamlessly enforce permissions while providing clear visual feedback about access levels and data source.Production Readiness
This feature enables SymptomSync to support real-world care coordination scenarios while maintaining its privacy-first architecture and providing the transparency and control users need when sharing sensitive health information.
Fixes #24.
Warning
Firewall rules blocked me from connecting to one or more addresses (expand for details)
I tried to connect to the following addresses, but was blocked by firewall rules:
fonts.googleapis.com/usr/local/bin/node /home/REDACTED/work/SymptomSync-Health-App/SymptomSync-Health-App/web/node_modules/next/dist/compiled/jest-worker/processChild.js(dns block)If you need me to access, download, or install something from one of these locations, you can either:
💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.