Sample code for 30+ languages & platforms
C

Set the Shared JWE Unprotected Header

See more JSON Web Encryption (JWE) Examples

Demonstrates Jwe.SetUnprotectedHeader, which sets the shared JWE unprotected header from a JsonObject.

Background. The unprotected header is shared by all recipients but, unlike the protected header, is not integrity-protected. It is carried in the JSON serialization forms of a JWE.

Chilkat C Downloads

C
#include <C_CkJwe.h>
#include <C_CkJsonObject.h>
#include <C_CkStringBuilder.h>

void ChilkatSample(void)
    {
    BOOL success;
    HCkJwe jwe;
    HCkJsonObject header;
    const char *base64Key;
    HCkJsonObject unprotected;
    HCkStringBuilder sbContent;
    HCkStringBuilder sbJwe;

    success = FALSE;

    jwe = CkJwe_Create();

    //  Protected header: AES key-wrap with AES-256-GCM content encryption.
    header = CkJsonObject_Create();
    CkJsonObject_UpdateString(header,"alg","A256KW");
    CkJsonObject_UpdateString(header,"enc","A256GCM");
    success = CkJwe_SetProtectedHeader(jwe,header);
    if (success == FALSE) {
        printf("%s\n",CkJwe_lastErrorText(jwe));
        CkJwe_Dispose(jwe);
        CkJsonObject_Dispose(header);
        return;
    }

    //  The 256-bit key-wrapping key (base64) for recipient index 0.  In production, obtain the key from a
    //  secure source rather than hard-coding it.
    base64Key = "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU=";
    success = CkJwe_SetWrappingKey(jwe,0,base64Key,"base64");
    if (success == FALSE) {
        printf("%s\n",CkJwe_lastErrorText(jwe));
        CkJwe_Dispose(jwe);
        CkJsonObject_Dispose(header);
        return;
    }

    //  Set the shared JWE unprotected header.  It is shared by all recipients but, unlike the protected
    //  header, is not integrity-protected.
    unprotected = CkJsonObject_Create();
    CkJsonObject_UpdateString(unprotected,"cty","text/plain");
    success = CkJwe_SetUnprotectedHeader(jwe,unprotected);
    if (success == FALSE) {
        printf("%s\n",CkJwe_lastErrorText(jwe));
        CkJwe_Dispose(jwe);
        CkJsonObject_Dispose(header);
        CkJsonObject_Dispose(unprotected);
        return;
    }

    sbContent = CkStringBuilder_Create();
    CkStringBuilder_Append(sbContent,"This is the secret content.");
    sbJwe = CkStringBuilder_Create();
    success = CkJwe_EncryptSb(jwe,sbContent,"utf-8",sbJwe);
    if (success == FALSE) {
        printf("%s\n",CkJwe_lastErrorText(jwe));
        CkJwe_Dispose(jwe);
        CkJsonObject_Dispose(header);
        CkJsonObject_Dispose(unprotected);
        CkStringBuilder_Dispose(sbContent);
        CkStringBuilder_Dispose(sbJwe);
        return;
    }

    printf("%s\n",CkStringBuilder_getAsString(sbJwe));


    CkJwe_Dispose(jwe);
    CkJsonObject_Dispose(header);
    CkJsonObject_Dispose(unprotected);
    CkStringBuilder_Dispose(sbContent);
    CkStringBuilder_Dispose(sbJwe);

    }