Sample code for 30+ languages & platforms
C

Set a Per-Recipient JWE Header

See more JSON Web Encryption (JWE) Examples

Demonstrates Jwe.SetRecipientHeader, which sets the per-recipient unprotected header for a recipient index.

Background. Per-recipient headers carry recipient-specific values such as a key id (kid), and are used with the JSON serialization forms that support multiple recipients.

Chilkat C Downloads

C
#include <C_CkJwe.h>
#include <C_CkJsonObject.h>
#include <C_CkStringBuilder.h>

void ChilkatSample(void)
    {
    BOOL success;
    HCkJwe jwe;
    HCkJsonObject header;
    const char *base64Key;
    HCkJsonObject recipHeader;
    HCkStringBuilder sbContent;
    HCkStringBuilder sbJwe;

    success = FALSE;

    jwe = CkJwe_Create();

    //  Protected header: AES key-wrap with AES-256-GCM content encryption.
    header = CkJsonObject_Create();
    CkJsonObject_UpdateString(header,"alg","A256KW");
    CkJsonObject_UpdateString(header,"enc","A256GCM");
    success = CkJwe_SetProtectedHeader(jwe,header);
    if (success == FALSE) {
        printf("%s\n",CkJwe_lastErrorText(jwe));
        CkJwe_Dispose(jwe);
        CkJsonObject_Dispose(header);
        return;
    }

    //  The 256-bit key-wrapping key (base64) for recipient index 0.  In production, obtain the key from a
    //  secure source rather than hard-coding it.
    base64Key = "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU=";
    success = CkJwe_SetWrappingKey(jwe,0,base64Key,"base64");
    if (success == FALSE) {
        printf("%s\n",CkJwe_lastErrorText(jwe));
        CkJwe_Dispose(jwe);
        CkJsonObject_Dispose(header);
        return;
    }

    //  Set the per-recipient unprotected header for recipient 0, for example a key id used to identify
    //  which key a recipient should use.
    recipHeader = CkJsonObject_Create();
    CkJsonObject_UpdateString(recipHeader,"kid","recipient-key-1");
    success = CkJwe_SetRecipientHeader(jwe,0,recipHeader);
    if (success == FALSE) {
        printf("%s\n",CkJwe_lastErrorText(jwe));
        CkJwe_Dispose(jwe);
        CkJsonObject_Dispose(header);
        CkJsonObject_Dispose(recipHeader);
        return;
    }

    sbContent = CkStringBuilder_Create();
    CkStringBuilder_Append(sbContent,"This is the secret content.");
    sbJwe = CkStringBuilder_Create();
    success = CkJwe_EncryptSb(jwe,sbContent,"utf-8",sbJwe);
    if (success == FALSE) {
        printf("%s\n",CkJwe_lastErrorText(jwe));
        CkJwe_Dispose(jwe);
        CkJsonObject_Dispose(header);
        CkJsonObject_Dispose(recipHeader);
        CkStringBuilder_Dispose(sbContent);
        CkStringBuilder_Dispose(sbJwe);
        return;
    }

    printf("%s\n",CkStringBuilder_getAsString(sbJwe));


    CkJwe_Dispose(jwe);
    CkJsonObject_Dispose(header);
    CkJsonObject_Dispose(recipHeader);
    CkStringBuilder_Dispose(sbContent);
    CkStringBuilder_Dispose(sbJwe);

    }