Skip to content

Connect an OHIF viewer

Goal: an OHIF viewer (or any DICOMweb viewer) searches and displays studies through the router, from the archives behind it, with each user signed in through your identity provider.

Tick Query/retrieve archive on each destination the viewer should search (Retrieve: through the router).

Configuration › Settings › DICOMweb:

  • DICOMweb port: 8443. Nodes serve it over HTTPS with their certificate, so give the nodes a certificate the viewer’s users’ browsers trust.
  • Web viewers allowed (origins): the viewer’s own address, such as https://viewer.example.org, so browsers may call the router from it.

Either of these:

  • Users signed in to the viewer (best): set DICOMweb sign-in: identity provider (your provider’s issuer URL) and Accepted audiences (the audience of its access tokens). Then, on a source, tick May query and retrieve and list the groups or roles whose users may use it, each with a short name for the history. The audit log names each user.
  • One token for the viewer: on a source, tick May query and retrieve and Accept DICOMweb uploads from these senders, add a sender OHIF, and give the viewer its token. (The token lets it upload too, so prefer signed-in users.)

In OHIF’s configuration, point its DICOMweb data source at a node (or the load-balanced name):

qidoRoot: 'https://routes.example.org:8443/dicomweb',
wadoRoot: 'https://routes.example.org:8443/dicomweb',

With an identity provider, configure OHIF’s OpenID Connect sign-in (its oidc section) with the same provider, asking for a token with the audience set in step 3; OHIF then sends each user’s token with every request.

Open the viewer, search for a patient: studies from every archive appear in one list. Opening one streams the images as they arrive from the archive. Every search and view is in the audit log.

See DICOMweb.