Skip to content
This repository has been archived by the owner on May 16, 2023. It is now read-only.

Documentation on warning on behalf is missing #701

Open
rugk opened this issue Sep 8, 2021 · 10 comments
Open

Documentation on warning on behalf is missing #701

rugk opened this issue Sep 8, 2021 · 10 comments
Labels
bug Something isn't working documentation Improvements or additions to documentation

Comments

@rugk
Copy link
Contributor

rugk commented Sep 8, 2021

Where to find the issue

https://github.com/corona-warn-app/cwa-documentation/blob/master/event_registration.md

Possibly https://github.com/corona-warn-app/cwa-verification-server/blob/master/docs/architecture-overview.md (last changed in 2020, so nothing new here).

Describe the issue

Since the latest v2.9 of the CWA, the health can warn users of the CWA even if the person who was tested positive cannot or does not warn others.

I tried to find technical information/documentation about how that new feature was implemented, but could not find any information.

Suggested change

This very likely includes at least:

  • …how the apps handle this (do they even handle it differently, or is it just some "ghost user" who is the health authority which is then added or what?)
  • How the server infrastructure was changed/is currently, to allow this feature? (if so)
  • How the TAN is generated and how it is assured that only authenticated parties (health authorities) can do this?
  • What happens if the key or whatever is used for one health authority is compromised?
@rugk rugk added bug Something isn't working documentation Improvements or additions to documentation labels Sep 8, 2021
@Ein-Tim
Copy link
Contributor

Ein-Tim commented Sep 8, 2021

BTW, https://github.com/corona-warn-app/cwa-documentation/blob/master/event_registration.md is outdated, it says:

CWA proposes a fully-automated decentral solution for Presence Tracing which works independent of local health authorities and the collaboration of the host of a venue.

Yes, it can work like this, but the document should be updated to reflect the new "Warn for others" feature 😅

Hope it's ok to add this here.

@rugk
Copy link
Contributor Author

rugk commented Sep 8, 2021

Yep, that's totally related and should/can be done when the doc for this whole feature is added.

rugk added a commit to rugk/cwa-documentation that referenced this issue Sep 8, 2021
This addresses a part of corona-warn-app#701 i.e. corona-warn-app#701 (comment) by implicitly saying that it can also work _with_ health authorities while it can also work _without_ them.
The claim that it never works without them is just no longer true since v2.9.

This is the most simple (and subtle) way to address it. But it fixes the now wrong statement in the doc.
Of course, the main issue to document the whole new feature with more technical details is still open.
@rugk
Copy link
Contributor Author

rugk commented Sep 8, 2021

So now submitted a simple "fix" for that wrong sentence: #703

@Ein-Tim
Copy link
Contributor

Ein-Tim commented Sep 9, 2021

FYI, on Twitter, somebody told me this:

Das funktioniert erstmal nur als Pilot mit zwei GÄ in Sachsen!
Die rufen eine Hotline an, bekommen dann eine TAN und warnen entweder selbst über die CWA oder geben die TAN an den Ersteller weiter.
Das Feature wird dann sukzessive an weitere GÄ ausgerollt.

No idea where they got this info, but is this true @thomasaugsten?

@thomasaugsten
Copy link
Member

  • The app handling is the same only the backend checks if not a regular tele-tan is used for warning on behalf or ENF keys are submitted.
  • A special tele-tan type was introduced
  • There is a special hotline only known to the GAs they have to call the hotline number and goes through a verification process to receive a tele-tan
  • There is no special key involved only a tele-tan with limited validity

I'm not in the rollout plan of the GAs involved.

@Ein-Tim
Copy link
Contributor

Ein-Tim commented Sep 9, 2021

@thomasaugsten

Okay thanks. But you can confirm that there is a staged roll out for this feature in the health authorities?

@thomasaugsten
Copy link
Member

I have no information about internal processes of the health authorities

@Ein-Tim
Copy link
Contributor

Ein-Tim commented Sep 9, 2021

Okay, I understand 😅

Thanks for your answers @thomasaugsten!

@Ein-Tim
Copy link
Contributor

Ein-Tim commented Apr 18, 2022

@dsarkar I suggest to mirror this issue to JIRA, the best title is probably "Documentation on warning on behalf is missing"

@rugk rugk changed the title Document technical details on how health authorities can trigger a warning on behalf of a person who tested positive Documentation on warning on behalf is missing Apr 19, 2022
@Ein-Tim
Copy link
Contributor

Ein-Tim commented May 13, 2023

The warning on behalf feature has been removed in version 2.28. - Documentation still would have been nice.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
bug Something isn't working documentation Improvements or additions to documentation
Projects
None yet
Development

No branches or pull requests

3 participants