Class OID4VCIssuedAtTimeClaimMapper

java.lang.Object
org.keycloak.protocol.oid4vc.issuance.mappers.OID4VCMapper
org.keycloak.protocol.oid4vc.issuance.mappers.OID4VCIssuedAtTimeClaimMapper
All Implemented Interfaces:
OID4VCEnvironmentProviderFactory, ProtocolMapper, ConfiguredProvider, EnvironmentDependentProviderFactory, Provider, ProviderFactory<ProtocolMapper>

public class OID4VCIssuedAtTimeClaimMapper extends OID4VCMapper
Map issuance date to the credential, under the default claim name "iat"

subjectProperty can be used to change the claim name.

Source of the information can either be computed, or read from the VerifiableCredential object bearing other claims. Default is the value in the verifiable credential.

We will use the java.time.temporal.ChronoUnit enum values to help flatten down the time.

NOTE: For SD-JWT credentials, this mapper has no effect on `iat` and `exp` claims, which are always sourced from the normalized issuance and expiration date values computed by the Issuer Endpoint.

Author:
Francis Pouatcha
  • Field Details

  • Constructor Details

    • OID4VCIssuedAtTimeClaimMapper

      public OID4VCIssuedAtTimeClaimMapper()
  • Method Details

    • getIndividualConfigProperties

      protected List<ProviderConfigProperty> getIndividualConfigProperties()
      Specified by:
      getIndividualConfigProperties in class OID4VCMapper
    • includeInMetadata

      public boolean includeInMetadata()
      this claim is not added by default to the metadata
      Overrides:
      includeInMetadata in class OID4VCMapper
    • supportsCredentialFormat

      public boolean supportsCredentialFormat(String credentialFormat)
      Description copied from class: OID4VCMapper
      Some mappers target format-specific container fields instead of subject/data-element claims. Callers use this hook for both metadata and issuance so unsupported mappers are not advertised or applied for a credential format.
      Overrides:
      supportsCredentialFormat in class OID4VCMapper
    • getAllowedReservedClaims

      protected Set<String> getAllowedReservedClaims()
      Description copied from class: OID4VCMapper
      Returns the reserved, issuer-controlled claims this mapper is allowed to write. A mapper may only target a reserved claim listed here; every other reserved claim is rejected. Mappers are denied all reserved claims by default; subclasses that legitimately write a specific issuer-controlled claim (e.g. the generated-id mapper writing 'jti') override this to allow just that claim.
      Overrides:
      getAllowedReservedClaims in class OID4VCMapper
    • setClaim

      public void setClaim(VerifiableCredential verifiableCredential, UserSessionModel userSessionModel)
      Description copied from class: OID4VCMapper
      Set the claims to credential, like f.e. the context
      Specified by:
      setClaim in class OID4VCMapper
    • setClaim

      public void setClaim(Map<String,Object> claims, UserSessionModel userSessionModel)
      Description copied from class: OID4VCMapper
      Set the claims to the credential subject.
      Specified by:
      setClaim in class OID4VCMapper
    • getDisplayType

      public String getDisplayType()
    • getHelpText

      public String getHelpText()
    • create

      public ProtocolMapper create(KeycloakSession session)
    • getId

      public String getId()