Class OID4VCMapper
java.lang.Object
org.keycloak.protocol.oid4vc.issuance.mappers.OID4VCMapper
- All Implemented Interfaces:
OID4VCEnvironmentProviderFactory,ProtocolMapper,ConfiguredProvider,EnvironmentDependentProviderFactory,Provider,ProviderFactory<ProtocolMapper>
- Direct Known Subclasses:
OID4VCContextMapper,OID4VCGeneratedIdMapper,OID4VCIssuedAtTimeClaimMapper,OID4VCStaticClaimMapper,OID4VCSubjectIdMapper,OID4VCTargetRoleMapper,OID4VCTypeMapper,OID4VCUserAttributeMapper
public abstract class OID4VCMapper
extends Object
implements ProtocolMapper, OID4VCEnvironmentProviderFactory
Base class for OID4VC Mappers, to provide common configuration and functionality for all of them
- Author:
- Stefan Wiedemann
-
Field Summary
Fields -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoidclose()This is called when the server shuts down.Returns the reserved, issuer-controlled claims this mapper is allowed to write.Returns the raw claim lookup path in the intermediate map populated bysetClaim(Map, UserSessionModel).getClaimLookupPath(String claimName) protected Stringprotected StringgetClaimName(String defaultClaimName) protected abstract List<ProviderConfigProperty>Returns the externally visible claim path used in credential metadata and authorization_details validation.getMetadataAttributePath(String attributeName) booleansome specific claims should not be added into the metadata.voidinit(Config.Scope scope) Only called once when the factory is first created.booleanReturnstruewhen this mapper passes all issuance-time guards.voidpostInit(KeycloakSessionFactory keycloakSessionFactory) Called after all provider factories have been initializedprefixMetadataAttributePath(List<String> attributePath) protected StringresolveClaimName(ProtocolMapperModel mapperModel) Resolves the effective claim name written by this mapper, based on the given configuration.abstract voidsetClaim(Map<String, Object> claims, UserSessionModel userSessionModel) Set the claims to the credential subject.abstract voidsetClaim(VerifiableCredential verifiableCredential, UserSessionModel userSessionModel) Set the claims to credential, like f.e. the contextvoidCopies the mapper claim value intoclaimsWithPrefixusing the externally visible credential path.setMapperModel(ProtocolMapperModel mapperModel, String format) booleansupportsCredentialFormat(String credentialFormat) Some mappers target format-specific container fields instead of subject/data-element claims.voidvalidate()Runs all validations (credential-format and sensitive-mapping checks) for this mapper.protected voidvalidateAgainstSensitiveMappings(String credentialFormat, ProtocolMapperModel mapperModel) Rejects a mapper whose configured claim name targets a reserved, issuer-controlled claim (e.g. exp, iat, sub, jti) unless the mapper is explicitly allowed to write that claim (seegetAllowedReservedClaims()).voidvalidateConfig(KeycloakSession session, RealmModel realm, ProtocolMapperContainerModel client, ProtocolMapperModel mapperModel) Called when instance of mapperModel is created/updated for this protocolMapper through admin endpointvoidvalidateMdocNamespace(String credentialFormat) Revalidates this mapper's namespace against the given format.Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface org.keycloak.provider.ConfiguredProvider
getConfig, getHelpTextMethods inherited from interface org.keycloak.protocol.oid4vc.OID4VCEnvironmentProviderFactory
isSupportedMethods inherited from interface org.keycloak.protocol.ProtocolMapper
getDisplayType, getEffectiveModel, getPriorityMethods inherited from interface org.keycloak.provider.ProviderFactory
create, dependsOn, getConfigMetadata, getId, order
-
Field Details
-
CLAIM_NAME
- See Also:
-
MDOC_NAMESPACE
- See Also:
-
USER_ATTRIBUTE_KEY
- See Also:
-
MAPPER_RESERVED_CLAIM_ERROR
- See Also:
-
MAPPER_MISSING_MDOC_NAMESPACE_ERROR
- See Also:
-
mapperModel
-
format
-
-
Constructor Details
-
OID4VCMapper
public OID4VCMapper()
-
-
Method Details
-
getIndividualConfigProperties
-
getMapperName
-
getConfigProperties
- Specified by:
getConfigPropertiesin interfaceConfiguredProvider
-
setMapperModel
-
validateConfig
public void validateConfig(KeycloakSession session, RealmModel realm, ProtocolMapperContainerModel client, ProtocolMapperModel mapperModel) throws ProtocolMapperConfigException Description copied from interface:ProtocolMapperCalled when instance of mapperModel is created/updated for this protocolMapper through admin endpoint- Specified by:
validateConfigin interfaceProtocolMapperclient- client or clientTemplate- Throws:
ProtocolMapperConfigException- if configuration provided in mapperModel is not valid
-
validate
Runs all validations (credential-format and sensitive-mapping checks) for this mapper. Because scope updates/imports can bypassvalidateConfig(org.keycloak.models.KeycloakSession, org.keycloak.models.RealmModel, org.keycloak.models.ProtocolMapperContainerModel, org.keycloak.models.ProtocolMapperModel), the issuer endpoint invokes this centrally at issuance so a misconfigured mapper fails the request instead of emitting broken or overridden claims.- Throws:
ProtocolMapperConfigException
-
passesMappingGuards
public boolean passesMappingGuards()Returnstruewhen this mapper passes all issuance-time guards. Used where a misconfigured mapper is silently omitted (e.g. from issuer metadata) rather than failing the request. -
validateAgainstSensitiveMappings
protected void validateAgainstSensitiveMappings(String credentialFormat, ProtocolMapperModel mapperModel) throws ProtocolMapperConfigException Rejects a mapper whose configured claim name targets a reserved, issuer-controlled claim (e.g. exp, iat, sub, jti) unless the mapper is explicitly allowed to write that claim (seegetAllowedReservedClaims()). Such a mapping could let a mapper override issuer-controlled claims (see keycloak/keycloak#52667).- Throws:
ProtocolMapperConfigException
-
validateMdocNamespace
Revalidates this mapper's namespace against the given format. Switching a client scope to mso_mdoc through the format selector does not runvalidateConfig(org.keycloak.models.KeycloakSession, org.keycloak.models.RealmModel, org.keycloak.models.ProtocolMapperContainerModel, org.keycloak.models.ProtocolMapperModel), so issuance uses this to reject an already stored claim mapper that is missing a namespace before it produces broken claims.- Throws:
ProtocolMapperConfigException
-
includeInMetadata
public boolean includeInMetadata()some specific claims should not be added into the metadata. Examples are jti, sub, iss etc. Since we have the possibility to add these credentials with specific claims we should also be able to exclude these specific attributes from the metadata -
supportsCredentialFormat
Some mappers target format-specific container fields instead of subject/data-element claims. Callers use this hook for both metadata and issuance so unsupported mappers are not advertised or applied for a credential format. -
getMetadataAttributePath
Returns the externally visible claim path used in credential metadata and authorization_details validation. JSON credentials use their normal credentialSubject/top-level paths; mDoc prepends the configured namespace because OID4VCI mDoc paths address namespace -> data element -> optional nested value. -
getMetadataAttributePath
-
prefixMetadataAttributePath
-
getClaimLookupPath
Returns the raw claim lookup path in the intermediate map populated bysetClaim(Map, UserSessionModel). This is intentionally separate fromgetMetadataAttributePath(): mDoc metadata paths add a namespace that is not present in the raw mapper output, and simple mappers may write a dotted claim name as one literal key. -
getClaimLookupPath
-
getClaimName
-
getClaimName
-
getAttributePrefix
-
getProtocol
- Specified by:
getProtocolin interfaceProtocolMapper
-
getDisplayCategory
- Specified by:
getDisplayCategoryin interfaceProtocolMapper
-
init
Description copied from interface:ProviderFactoryOnly called once when the factory is first created.- Specified by:
initin interfaceProviderFactory<ProtocolMapper>
-
postInit
Description copied from interface:ProviderFactoryCalled after all provider factories have been initialized- Specified by:
postInitin interfaceProviderFactory<ProtocolMapper>
-
close
public void close()Description copied from interface:ProviderFactoryThis is called when the server shuts down.- Specified by:
closein interfaceProvider- Specified by:
closein interfaceProviderFactory<ProtocolMapper>
-
setClaim
public abstract void setClaim(VerifiableCredential verifiableCredential, UserSessionModel userSessionModel) Set the claims to credential, like f.e. the context -
setClaim
Set the claims to the credential subject. -
setClaimWithMetadataPrefix
public void setClaimWithMetadataPrefix(Map<String, Object> claimsOrig, Map<String, Object> claimsWithPrefix) Copies the mapper claim value intoclaimsWithPrefixusing the externally visible credential path. This is used for authorization_details validation and for mDoc issuance, where the credential subject is namespace-shaped even though individual mappers write un-namespaced raw claims.- Parameters:
claimsOrig- Map with the original claims, which were returned bysetClaim(Map, UserSessionModel). This method usually just reads from this mapclaimsWithPrefix- Map with the claims including path prefix. This method might write to this map
-
getAllowedReservedClaims
Returns the reserved, issuer-controlled claims this mapper is allowed to write. A mapper may only target a reserved claim listed here; every other reserved claim is rejected. Mappers are denied all reserved claims by default; subclasses that legitimately write a specific issuer-controlled claim (e.g. the generated-id mapper writing 'jti') override this to allow just that claim. -
resolveClaimName
Resolves the effective claim name written by this mapper, based on the given configuration. Subclasses override this when they derive the claim name with a fallback (e.g. user attribute or a default claim name).
-