Class JsonLdContextDocumentLoader
java.lang.Object
org.keycloak.protocol.oid4vc.issuance.signing.vcdm.JsonLdContextDocumentLoader
- All Implemented Interfaces:
com.apicatalog.jsonld.loader.DocumentLoader
public class JsonLdContextDocumentLoader
extends Object
implements com.apicatalog.jsonld.loader.DocumentLoader
A
DocumentLoader for the JSON-LD @context documents referenced by linked-data
verifiable credentials (LDP_VC). It hardens the default loader of the JSON-LD library, which
otherwise issues a fresh, uncached HTTP GET per context URL on every credential issuance,
without a request timeout or any restriction on the target:
- Allowlist - only
httpsis permitted and the host of every context URL must be inDEFAULT_ALLOWED_HOSTS. The policy applies to the initial URL and to every redirect hop. - Cache - context documents are cached in memory in a bounded LRU cache keyed by URL, so each context is fetched at most once per server lifetime. Contexts are stable, so caching avoids repeated outbound requests and signature inconsistencies caused by content drift between issuances.
- Transport - requests are sent through Keycloak's configured
HttpClientProviderclient, so the server's proxy, TLS and timeout settings apply. The response body is consumed with a size limit, so an oversized or stalled context host cannot exhaust the heap or block the credential-issuance worker thread indefinitely.
-
Field Summary
FieldsModifier and TypeFieldDescriptionWell-known hosts serving stable JSON-LD context documents for verifiable credentials. -
Constructor Summary
ConstructorsConstructorDescriptionJsonLdContextDocumentLoader(org.apache.http.impl.client.CloseableHttpClient client) Creates a loader with the default https-only allowlist, using the given HTTP client. -
Method Summary
Modifier and TypeMethodDescriptionstatic com.apicatalog.jsonld.loader.DocumentLoaderdefaultInstance(KeycloakSession session) Returns the loader shared by all credential signing suites.com.apicatalog.jsonld.document.DocumentloadDocument(URI url, com.apicatalog.jsonld.loader.DocumentLoaderOptions options)
-
Field Details
-
DEFAULT_ALLOWED_HOSTS
Well-known hosts serving stable JSON-LD context documents for verifiable credentials.digitalbazaar.github.iois included because the standard security-suite contexts onw3id.orgare served through a redirect to that host.
-
-
Constructor Details
-
JsonLdContextDocumentLoader
public JsonLdContextDocumentLoader(org.apache.http.impl.client.CloseableHttpClient client) Creates a loader with the default https-only allowlist, using the given HTTP client.
-
-
Method Details
-
defaultInstance
Returns the loader shared by all credential signing suites. The loader is created once per server lifetime from the platform HTTP client, so the context cache is shared across issuances and every request honors the server's outbound HTTP configuration. -
loadDocument
public com.apicatalog.jsonld.document.Document loadDocument(URI url, com.apicatalog.jsonld.loader.DocumentLoaderOptions options) throws com.apicatalog.jsonld.JsonLdError - Specified by:
loadDocumentin interfacecom.apicatalog.jsonld.loader.DocumentLoader- Throws:
com.apicatalog.jsonld.JsonLdError
-