Class KeycloakTrustAnchorRepository

java.lang.Object
org.keycloak.authentication.requiredactions.KeycloakTrustAnchorRepository
All Implemented Interfaces:
com.webauthn4j.anchor.TrustAnchorRepository

public class KeycloakTrustAnchorRepository extends Object implements com.webauthn4j.anchor.TrustAnchorRepository
Looks up TrustAnchors from the Keycloak TruststoreProvider on every call, without caching anything, unlike KeyStoreTrustAnchorRepository, which scans the whole KeyStore once in its constructor and caches the result forever.

which happens far less often than WebAuthnRegisterFactory.create(KeycloakSession) is called (once per login, merely to check whether the required action is triggered), so re-scanning the truststore here on each use is cheap enough that no caching is needed.

  • Constructor Details

    • KeycloakTrustAnchorRepository

      public KeycloakTrustAnchorRepository(KeycloakSession session)
  • Method Details

    • find

      public Set<TrustAnchor> find(com.webauthn4j.data.attestation.authenticator.AAGUID aaguid)
      Specified by:
      find in interface com.webauthn4j.anchor.TrustAnchorRepository
    • find

      public Set<TrustAnchor> find(byte[] attestationCertificateKeyIdentifier)
      Specified by:
      find in interface com.webauthn4j.anchor.TrustAnchorRepository