What your application does
The SDK does the cryptography and the protocol. Your application does the rest, for the reasons below.
| Your application | Because |
|---|---|
| Owns the surface: renders every listing, record, file, editor and what is signed. Lets nothing leave the surface except through a decided action | Plaintext exists only there. The SDK never keeps a copy once your open closes. |
| Obtains the person’s secret through the unlock adapter, and opens the identity provider in the system browser through the sign-in adapter | The SDK holds the device key. The person’s secret and their sign-in are yours to ask for. Each platform SDK decides how to lock the key with what the unlock adapter returns. |
| Shows the person what waits, and on whom: access for a new device, a queued group join, a draft, an offline lease’s expiry | The SDK reports these through events and the worklist. It does not show them to the person. Your application must show them. No person should wait without knowing why. |
Confirms who is asking, and compares the code, before calling approve() | The approver’s own judgment, not a cryptographic check, is the third factor an enrollment needs. The SDK computes the code. Only a person can confirm it matches and that the right person is asking. |
Carries out a Copy, Print, Download File or Access Record after an allow decision | The plaintext is already in your surface. The SDK decides whether the action may happen. Your application copies, prints or downloads it. |
States its kind and release in Config | The version floor is per ClientKind. The Seald Healthcare Cloud refuses a session below it. Only your application knows what it is and what release it ships. |
The browser extension also binds the page’s session
An extension additionally calls session.bindPage(pageSession). A call it makes on behalf of the
dashboard page then carries both sessions at once. The Seald Healthcare Cloud answers only when they name the
same person:
client.session.bindPage(pageSession); // sends both sessions on every call for the pageclient.session.bindPage(pageSession) // sends both sessions on every call for the pageclient.session.bindPage(pageSession) // sends both sessions on every call for the pagePassing undefined unbinds it. See Browser extension for the full
flow, including the hostname check. A page on any other origin gets nothing.
Next
- What the SDK does for you for the other half of the split.
- Adapters for
unlock,signIn,attestationandofflineMedium. - Browser extension for
bindPagein context.