Class OID4VCSubjectIdMapper
java.lang.Object
org.keycloak.protocol.oid4vc.issuance.mappers.OID4VCMapper
org.keycloak.protocol.oid4vc.issuance.mappers.OID4VCSubjectIdMapper
- All Implemented Interfaces:
OID4VCEnvironmentProviderFactory,ProtocolMapper,ConfiguredProvider,EnvironmentDependentProviderFactory,Provider,ProviderFactory<ProtocolMapper>
Sets an ID for the credential subject, either from User ID or by attribute mapping.
The subject ID defaults to the user's username but can be configured to use email or internal ID.
- Author:
- Stefan Wiedemann
-
Field Summary
FieldsFields inherited from class org.keycloak.protocol.oid4vc.issuance.mappers.OID4VCMapper
CLAIM_NAME, format, MAPPER_MISSING_MDOC_NAMESPACE_ERROR, MAPPER_RESERVED_CLAIM_ERROR, mapperModel, MDOC_NAMESPACE, USER_ATTRIBUTE_KEY -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionstatic ProtocolMapperModelcreate(KeycloakSession session) Returns the reserved, issuer-controlled claims this mapper is allowed to write.Returns the raw claim lookup path in the intermediate map populated byOID4VCMapper.setClaim(Map, UserSessionModel).getId()protected List<ProviderConfigProperty>Returns the externally visible claim path used in credential metadata and authorization_details validation.protected StringresolveClaimName(ProtocolMapperModel mapperModel) Resolves the effective claim name written by this mapper, based on the given configuration.voidsetClaim(Map<String, Object> claims, UserSessionModel userSessionModel) Set the claims to the credential subject.voidsetClaim(VerifiableCredential verifiableCredential, UserSessionModel userSessionModel) Set the claims to credential, like f.e. the contextMethods inherited from class org.keycloak.protocol.oid4vc.issuance.mappers.OID4VCMapper
close, getAttributePrefix, getClaimLookupPath, getClaimName, getClaimName, getConfigProperties, getDisplayCategory, getMapperName, getMetadataAttributePath, getProtocol, includeInMetadata, init, passesMappingGuards, postInit, prefixMetadataAttributePath, setClaimWithMetadataPrefix, setMapperModel, supportsCredentialFormat, validate, validateAgainstSensitiveMappings, validateConfig, validateMdocNamespaceMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface org.keycloak.provider.ConfiguredProvider
getConfigMethods inherited from interface org.keycloak.protocol.oid4vc.OID4VCEnvironmentProviderFactory
isSupportedMethods inherited from interface org.keycloak.protocol.ProtocolMapper
getEffectiveModel, getPriorityMethods inherited from interface org.keycloak.provider.ProviderFactory
dependsOn, getConfigMetadata, order
-
Field Details
-
MAPPER_ID
- See Also:
-
-
Constructor Details
-
OID4VCSubjectIdMapper
public OID4VCSubjectIdMapper()
-
-
Method Details
-
create
-
getIndividualConfigProperties
- Specified by:
getIndividualConfigPropertiesin classOID4VCMapper
-
setClaim
Description copied from class:OID4VCMapperSet the claims to credential, like f.e. the context- Specified by:
setClaimin classOID4VCMapper
-
setClaim
Description copied from class:OID4VCMapperSet the claims to the credential subject.- Specified by:
setClaimin classOID4VCMapper
-
resolveClaimName
Description copied from class:OID4VCMapperResolves the effective claim name written by this mapper, based on the given configuration. Subclasses override this when they derive the claim name with a fallback (e.g. user attribute or a default claim name).- Overrides:
resolveClaimNamein classOID4VCMapper
-
getMetadataAttributePath
Description copied from class:OID4VCMapperReturns the externally visible claim path used in credential metadata and authorization_details validation. JSON credentials use their normal credentialSubject/top-level paths; mDoc prepends the configured namespace because OID4VCI mDoc paths address namespace -> data element -> optional nested value.- Overrides:
getMetadataAttributePathin classOID4VCMapper
-
getClaimLookupPath
Description copied from class:OID4VCMapperReturns the raw claim lookup path in the intermediate map populated byOID4VCMapper.setClaim(Map, UserSessionModel). This is intentionally separate fromOID4VCMapper.getMetadataAttributePath(): mDoc metadata paths add a namespace that is not present in the raw mapper output, and simple mappers may write a dotted claim name as one literal key.- Overrides:
getClaimLookupPathin classOID4VCMapper
-
getDisplayType
-
getHelpText
-
create
-
getAllowedReservedClaims
Description copied from class:OID4VCMapperReturns the reserved, issuer-controlled claims this mapper is allowed to write. A mapper may only target a reserved claim listed here; every other reserved claim is rejected. Mappers are denied all reserved claims by default; subclasses that legitimately write a specific issuer-controlled claim (e.g. the generated-id mapper writing 'jti') override this to allow just that claim.- Overrides:
getAllowedReservedClaimsin classOID4VCMapper
-
getId
-