Skip to content

JSON-LD: always apply jsonld.contexts.remoteallowlist, also when strict mode is off #4618

Description

@reinkrul

Context

Follow-up to #4615 / #4617. That fix bounds remote JSON-LD context fetches with a timeout and a failure cache. This issue removes the reason those fetches happen in the first place: in non-strict mode, the node fetches any context URL a credential refers to.

Problem

jsonld/jsonld.go builds the loader with NewContextLoader(!serverConfig.Strictmode, ...). When strict mode is off, NewContextLoader (jsonld/ldutils.go) skips the filteredDocumentLoader, so jsonld.contexts.remoteallowlist has no effect and every unknown context is fetched from the internet while the credential is verified.

  • Untrusted input drives outbound requests. Credentials from the network and presentations received over HTTP choose the URLs.
  • Verification depends on third-party servers. A slow or dead server stalls processing (bounded to 5 s by JSON-LD: time out remote context fetches and remember failures #4617). A changed context silently changes how credentials expand.
  • Unbounded caching. json-gold's CachingDocumentLoader keeps every successfully fetched URL forever.
  • Little value in practice. All default contexts are embedded. In a production DAG dump, the only two contexts that need a remote fetch both fail: one returns 404, the other never answers Go clients.
Mode Unlisted context today Proposed (v7)
strict rejected: context not on the remoteallowlist unchanged
non-strict fetched from the internet rejected: context not on the remoteallowlist

Proposal

v7: always apply the allow list

  • NewContextLoader always wraps the chain in filteredDocumentLoader. Drop the allowUnlistedExternalCalls parameter. jsonld.go no longer passes !Strictmode.
  • Unlisted contexts end with jsonld.ContextURLNotAllowedErr. vcr/ambassador.go handleError already treats that as "ignored, finished", so the event is not retried.
  • Flag help in jsonld/cmd.go changes from "In strict mode, fetching external JSON-LD contexts is not allowed except for context-URLs listed here." to "Fetching external JSON-LD contexts is not allowed except for context-URLs listed here."
  • Docs: docs/pages/deployment/verifiable-credentials.rst (fetching section) and the strict mode list in docs/pages/deployment/configuration.rst.
  • Release notes: breaking change, with the migration step below.

Migration for operators that use custom contexts without listing them: add the URL to jsonld.contexts.remoteallowlist, or pin it with jsonld.contexts.localmapping. Setting either list replaces the defaults, so the default entries must be repeated (see the note in the docs).

v6.x minor: deprecation warning

Before v7, log a warning when a non-strict node fetches a context that is not on the allow list, naming the URL and stating that v7 will require it to be listed. Log once per URL, not per credential. Master only, not backported to patch releases.

Scope

  • jsonld/ldutils.go (NewContextLoader), jsonld/jsonld.go, jsonld/cmd.go
  • Tests in jsonld/ldutils_test.go that construct the loader with true
  • Docs, release notes, the generated options table

Considerations

  • Developer experience: trying out a custom credential type now needs one config entry. The error message already names the setting.
  • After this change, strict mode no longer influences JSON-LD loading. The strict mode docs should drop the JSON-LD line rather than keep a misleading one.

Backport

None, master only (v7). The deprecation warning goes into the next 6.x minor release from master.

Related

Activity

  1. added this to the v7 milestone on Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions