C
C
Set a Per-Recipient JWE Header
See more JSON Web Encryption (JWE) Examples
Demonstrates Jwe.SetRecipientHeader, which sets the per-recipient unprotected header for a recipient index.
Background. Per-recipient headers carry recipient-specific values such as a key id (
kid), and are used with the JSON serialization forms that support multiple recipients.Chilkat C Downloads
#include <C_CkJwe.h>
#include <C_CkJsonObject.h>
#include <C_CkStringBuilder.h>
void ChilkatSample(void)
{
BOOL success;
HCkJwe jwe;
HCkJsonObject header;
const char *base64Key;
HCkJsonObject recipHeader;
HCkStringBuilder sbContent;
HCkStringBuilder sbJwe;
success = FALSE;
jwe = CkJwe_Create();
// Protected header: AES key-wrap with AES-256-GCM content encryption.
header = CkJsonObject_Create();
CkJsonObject_UpdateString(header,"alg","A256KW");
CkJsonObject_UpdateString(header,"enc","A256GCM");
success = CkJwe_SetProtectedHeader(jwe,header);
if (success == FALSE) {
printf("%s\n",CkJwe_lastErrorText(jwe));
CkJwe_Dispose(jwe);
CkJsonObject_Dispose(header);
return;
}
// The 256-bit key-wrapping key (base64) for recipient index 0. In production, obtain the key from a
// secure source rather than hard-coding it.
base64Key = "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU=";
success = CkJwe_SetWrappingKey(jwe,0,base64Key,"base64");
if (success == FALSE) {
printf("%s\n",CkJwe_lastErrorText(jwe));
CkJwe_Dispose(jwe);
CkJsonObject_Dispose(header);
return;
}
// Set the per-recipient unprotected header for recipient 0, for example a key id used to identify
// which key a recipient should use.
recipHeader = CkJsonObject_Create();
CkJsonObject_UpdateString(recipHeader,"kid","recipient-key-1");
success = CkJwe_SetRecipientHeader(jwe,0,recipHeader);
if (success == FALSE) {
printf("%s\n",CkJwe_lastErrorText(jwe));
CkJwe_Dispose(jwe);
CkJsonObject_Dispose(header);
CkJsonObject_Dispose(recipHeader);
return;
}
sbContent = CkStringBuilder_Create();
CkStringBuilder_Append(sbContent,"This is the secret content.");
sbJwe = CkStringBuilder_Create();
success = CkJwe_EncryptSb(jwe,sbContent,"utf-8",sbJwe);
if (success == FALSE) {
printf("%s\n",CkJwe_lastErrorText(jwe));
CkJwe_Dispose(jwe);
CkJsonObject_Dispose(header);
CkJsonObject_Dispose(recipHeader);
CkStringBuilder_Dispose(sbContent);
CkStringBuilder_Dispose(sbJwe);
return;
}
printf("%s\n",CkStringBuilder_getAsString(sbJwe));
CkJwe_Dispose(jwe);
CkJsonObject_Dispose(header);
CkJsonObject_Dispose(recipHeader);
CkStringBuilder_Dispose(sbContent);
CkStringBuilder_Dispose(sbJwe);
}