C
C
Set the Shared JWE Unprotected Header
See more JSON Web Encryption (JWE) Examples
Demonstrates Jwe.SetUnprotectedHeader, which sets the shared JWE unprotected header from a JsonObject.
Background. The unprotected header is shared by all recipients but, unlike the protected header, is not integrity-protected. It is carried in the JSON serialization forms of a JWE.
Chilkat C Downloads
#include <C_CkJwe.h>
#include <C_CkJsonObject.h>
#include <C_CkStringBuilder.h>
void ChilkatSample(void)
{
BOOL success;
HCkJwe jwe;
HCkJsonObject header;
const char *base64Key;
HCkJsonObject unprotected;
HCkStringBuilder sbContent;
HCkStringBuilder sbJwe;
success = FALSE;
jwe = CkJwe_Create();
// Protected header: AES key-wrap with AES-256-GCM content encryption.
header = CkJsonObject_Create();
CkJsonObject_UpdateString(header,"alg","A256KW");
CkJsonObject_UpdateString(header,"enc","A256GCM");
success = CkJwe_SetProtectedHeader(jwe,header);
if (success == FALSE) {
printf("%s\n",CkJwe_lastErrorText(jwe));
CkJwe_Dispose(jwe);
CkJsonObject_Dispose(header);
return;
}
// The 256-bit key-wrapping key (base64) for recipient index 0. In production, obtain the key from a
// secure source rather than hard-coding it.
base64Key = "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU=";
success = CkJwe_SetWrappingKey(jwe,0,base64Key,"base64");
if (success == FALSE) {
printf("%s\n",CkJwe_lastErrorText(jwe));
CkJwe_Dispose(jwe);
CkJsonObject_Dispose(header);
return;
}
// Set the shared JWE unprotected header. It is shared by all recipients but, unlike the protected
// header, is not integrity-protected.
unprotected = CkJsonObject_Create();
CkJsonObject_UpdateString(unprotected,"cty","text/plain");
success = CkJwe_SetUnprotectedHeader(jwe,unprotected);
if (success == FALSE) {
printf("%s\n",CkJwe_lastErrorText(jwe));
CkJwe_Dispose(jwe);
CkJsonObject_Dispose(header);
CkJsonObject_Dispose(unprotected);
return;
}
sbContent = CkStringBuilder_Create();
CkStringBuilder_Append(sbContent,"This is the secret content.");
sbJwe = CkStringBuilder_Create();
success = CkJwe_EncryptSb(jwe,sbContent,"utf-8",sbJwe);
if (success == FALSE) {
printf("%s\n",CkJwe_lastErrorText(jwe));
CkJwe_Dispose(jwe);
CkJsonObject_Dispose(header);
CkJsonObject_Dispose(unprotected);
CkStringBuilder_Dispose(sbContent);
CkStringBuilder_Dispose(sbJwe);
return;
}
printf("%s\n",CkStringBuilder_getAsString(sbJwe));
CkJwe_Dispose(jwe);
CkJsonObject_Dispose(header);
CkJsonObject_Dispose(unprotected);
CkStringBuilder_Dispose(sbContent);
CkStringBuilder_Dispose(sbJwe);
}