OpenMRS Secure Coding

Categories: Security
Wishlist Share

About Course

This micro-course introduces OpenMRS developers to core security concepts that help protect users, patient data, and sensitive system operations. Through five short modules, developers will learn the difference between authentication and authorization, how OpenMRS roles and privileges control access, when and how proxy privileges should be used safely, how authenticated sessions work and must be protected, and how Cross-Site Request Forgery (CSRF) can abuse a user’s active session. The course emphasizes practical, secure development habits and provides developers with clear guidance for designing, implementing, and reviewing security-sensitive OpenMRS code.

Course Content

Introduction to OWASP
OpenMRS manages sensitive patient health records across a wide range of clinical environments. Security is not a separate workstream. It is part of how we build, deploy, and maintain the platform. This micro course introduces the Open Worldwide Application Security Project (OWASP) and their top 10 list of key security issues that are important to OpenMRS developers. It also introduces ways to avoid some types of vulnerabilities. This course is designed for OpenMRS core developers and is also recommended for developers working on country instances and implementations. After this course, learners will be able to:  Articulate the importance of the Open Worldwide Application Security Project (OWASP)  top 10  Identify the types of security categories that are in the OWASP top 10 Articulate why OWASP is important to OpenMRS Articulate best practices

  • OWASP Top 10
  • Why it Matters
  • The OWASP Top 10:2025 at a Glance
  • OWASP 2021 TO 2025
  • Pre-PR Security Checklist
  • OpenMRS Security Resources
  • Quiz 1

Authentication and Authorization Guidelines
This course is designed for OpenMRS core developers and is also recommended for developers working on country instances and implementations. After this course, learners will be able to: Define authentication and authorization and articulate the difference. Understand and apply the concept of least privilege. Understand the importance of secure front-end and back-end authorization coding practices. Apply appropriate CSFR practices in OpenMRS.

OpenMRS Vulnerability Testing
OpenMRS manages sensitive patient health records across a wide range of clinical environments, keeping them confidential and available while maintaining their integrity over time. Security is not a separate workstream. It is part of how we build, deploy, and maintain the platform. This micro course introduces the vulnerability dashboard, and the process to create vulnerability tests and add them to the vulnerability dashboard. After this course, learners will be able to:  Understanding the Dashboard Writing feature files Implementing feature files in Python Running tests & generating the dashboard

APIs and File Handling
OpenMRS manages sensitive patient health records across a wide range of clinical environments, keeping them confidential and available while maintaining their integrity over time. Security is not a separate workstream. It is part of how we build, deploy, and maintain the platform. This micro course introduces methods and techniques to securely develop REST APIs and avoid vulnerabilities associated with file handling. After this course, learners will be able to: Understand the risks of operating with data supplied by users Securely design and implement REST Apis Understand common risks and vulnerabilities when handling files Securely work with files and avoid common vulnerabilities

Earn a certificate

Add this certificate to your resume to demonstrate your skills & increase your chances of getting noticed.

selected template

Student Ratings & Reviews

No Review Yet
No Review Yet