Class OID4VCTargetRoleMapper
java.lang.Object
org.keycloak.protocol.oid4vc.issuance.mappers.OID4VCMapper
org.keycloak.protocol.oid4vc.issuance.mappers.OID4VCTargetRoleMapper
- All Implemented Interfaces:
OID4VCEnvironmentProviderFactory,ProtocolMapper,ConfiguredProvider,EnvironmentDependentProviderFactory,Provider,ProviderFactory<ProtocolMapper>
Adds the users roles to the credential subject
- Author:
- Stefan Wiedemann
-
Field Summary
FieldsFields inherited from class org.keycloak.protocol.oid4vc.issuance.mappers.OID4VCMapper
CLAIM_NAME, format, MAPPER_MISSING_MDOC_NAMESPACE_ERROR, MAPPER_RESERVED_CLAIM_ERROR, mapperModel, MDOC_NAMESPACE, USER_ATTRIBUTE_KEY -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionstatic ProtocolMapperModelcreate(KeycloakSession session) Returns the raw claim lookup path in the intermediate map populated byOID4VCMapper.setClaim(Map, UserSessionModel).getId()protected List<ProviderConfigProperty>Returns the externally visible claim path used in credential metadata and authorization_details validation.protected StringresolveClaimName(ProtocolMapperModel mapperModel) Resolves the effective claim name written by this mapper, based on the given configuration.voidsetClaim(Map<String, Object> claims, UserSessionModel userSessionModel) Set the claims to the credential subject.voidsetClaim(VerifiableCredential verifiableCredential, UserSessionModel userSessionModel) Set the claims to credential, like f.e. the contextvoidvalidateConfig(KeycloakSession session, RealmModel realm, ProtocolMapperContainerModel client, ProtocolMapperModel mapperModel) Called when instance of mapperModel is created/updated for this protocolMapper through admin endpointMethods inherited from class org.keycloak.protocol.oid4vc.issuance.mappers.OID4VCMapper
close, getAllowedReservedClaims, getAttributePrefix, getClaimLookupPath, getClaimName, getClaimName, getConfigProperties, getDisplayCategory, getMapperName, getMetadataAttributePath, getProtocol, includeInMetadata, init, passesMappingGuards, postInit, prefixMetadataAttributePath, setClaimWithMetadataPrefix, setMapperModel, supportsCredentialFormat, validate, validateAgainstSensitiveMappings, validateMdocNamespaceMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface org.keycloak.provider.ConfiguredProvider
getConfigMethods inherited from interface org.keycloak.protocol.oid4vc.OID4VCEnvironmentProviderFactory
isSupportedMethods inherited from interface org.keycloak.protocol.ProtocolMapper
getEffectiveModel, getPriorityMethods inherited from interface org.keycloak.provider.ProviderFactory
dependsOn, getConfigMetadata, order
-
Field Details
-
DEFAULT_CLAIM_NAME
- See Also:
-
CLIENT_CONFIG_KEY
- See Also:
-
MAPPER_ID
- See Also:
-
-
Constructor Details
-
OID4VCTargetRoleMapper
public OID4VCTargetRoleMapper() -
OID4VCTargetRoleMapper
-
-
Method Details
-
getIndividualConfigProperties
- Specified by:
getIndividualConfigPropertiesin classOID4VCMapper
-
resolveClaimName
Description copied from class:OID4VCMapperResolves the effective claim name written by this mapper, based on the given configuration. Subclasses override this when they derive the claim name with a fallback (e.g. user attribute or a default claim name).- Overrides:
resolveClaimNamein classOID4VCMapper
-
getMetadataAttributePath
Description copied from class:OID4VCMapperReturns the externally visible claim path used in credential metadata and authorization_details validation. JSON credentials use their normal credentialSubject/top-level paths; mDoc prepends the configured namespace because OID4VCI mDoc paths address namespace -> data element -> optional nested value.- Overrides:
getMetadataAttributePathin classOID4VCMapper
-
getClaimLookupPath
Description copied from class:OID4VCMapperReturns the raw claim lookup path in the intermediate map populated byOID4VCMapper.setClaim(Map, UserSessionModel). This is intentionally separate fromOID4VCMapper.getMetadataAttributePath(): mDoc metadata paths add a namespace that is not present in the raw mapper output, and simple mappers may write a dotted claim name as one literal key.- Overrides:
getClaimLookupPathin classOID4VCMapper
-
getDisplayType
-
getHelpText
-
create
-
create
-
validateConfig
public void validateConfig(KeycloakSession session, RealmModel realm, ProtocolMapperContainerModel client, ProtocolMapperModel mapperModel) throws ProtocolMapperConfigException Description copied from interface:ProtocolMapperCalled when instance of mapperModel is created/updated for this protocolMapper through admin endpoint- Specified by:
validateConfigin interfaceProtocolMapper- Overrides:
validateConfigin classOID4VCMapperclient- client or clientTemplate- Throws:
ProtocolMapperConfigException- if configuration provided in mapperModel is not valid
-
getId
-
setClaim
Description copied from class:OID4VCMapperSet the claims to credential, like f.e. the context- Specified by:
setClaimin classOID4VCMapper
-
setClaim
Description copied from class:OID4VCMapperSet the claims to the credential subject.- Specified by:
setClaimin classOID4VCMapper
-