Class JsonLdContextDocumentLoader

java.lang.Object
org.keycloak.protocol.oid4vc.issuance.signing.vcdm.JsonLdContextDocumentLoader
All Implemented Interfaces:
com.apicatalog.jsonld.loader.DocumentLoader

public class JsonLdContextDocumentLoader extends Object implements com.apicatalog.jsonld.loader.DocumentLoader
A DocumentLoader for the JSON-LD @context documents referenced by linked-data verifiable credentials (LDP_VC). It hardens the default loader of the JSON-LD library, which otherwise issues a fresh, uncached HTTP GET per context URL on every credential issuance, without a request timeout or any restriction on the target:
  • Allowlist - only https is permitted and the host of every context URL must be in DEFAULT_ALLOWED_HOSTS. The policy applies to the initial URL and to every redirect hop.
  • Cache - context documents are cached in memory in a bounded LRU cache keyed by URL, so each context is fetched at most once per server lifetime. Contexts are stable, so caching avoids repeated outbound requests and signature inconsistencies caused by content drift between issuances.
  • Transport - requests are sent through Keycloak's configured HttpClientProvider client, so the server's proxy, TLS and timeout settings apply. The response body is consumed with a size limit, so an oversized or stalled context host cannot exhaust the heap or block the credential-issuance worker thread indefinitely.
  • Field Summary

    Fields
    Modifier and Type
    Field
    Description
    static final Set<String>
    Well-known hosts serving stable JSON-LD context documents for verifiable credentials.
  • Constructor Summary

    Constructors
    Constructor
    Description
    JsonLdContextDocumentLoader(org.apache.http.impl.client.CloseableHttpClient client)
    Creates a loader with the default https-only allowlist, using the given HTTP client.
  • Method Summary

    Modifier and Type
    Method
    Description
    static com.apicatalog.jsonld.loader.DocumentLoader
    Returns the loader shared by all credential signing suites.
    com.apicatalog.jsonld.document.Document
    loadDocument(URI url, com.apicatalog.jsonld.loader.DocumentLoaderOptions options)
     

    Methods inherited from class java.lang.Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Field Details

    • DEFAULT_ALLOWED_HOSTS

      public static final Set<String> DEFAULT_ALLOWED_HOSTS
      Well-known hosts serving stable JSON-LD context documents for verifiable credentials. digitalbazaar.github.io is included because the standard security-suite contexts on w3id.org are served through a redirect to that host.
  • Constructor Details

    • JsonLdContextDocumentLoader

      public JsonLdContextDocumentLoader(org.apache.http.impl.client.CloseableHttpClient client)
      Creates a loader with the default https-only allowlist, using the given HTTP client.
  • Method Details

    • defaultInstance

      public static com.apicatalog.jsonld.loader.DocumentLoader defaultInstance(KeycloakSession session)
      Returns the loader shared by all credential signing suites. The loader is created once per server lifetime from the platform HTTP client, so the context cache is shared across issuances and every request honors the server's outbound HTTP configuration.
    • loadDocument

      public com.apicatalog.jsonld.document.Document loadDocument(URI url, com.apicatalog.jsonld.loader.DocumentLoaderOptions options) throws com.apicatalog.jsonld.JsonLdError
      Specified by:
      loadDocument in interface com.apicatalog.jsonld.loader.DocumentLoader
      Throws:
      com.apicatalog.jsonld.JsonLdError