C
C
REST Basic Auth with Secure Strings
Demonstrates how to do REST Basic authentication using secure strings.This example requires Chilkat v9.5.0.71 or greater.
Chilkat C Downloads
#include <C_CkJsonObject.h>
#include <C_CkCrypt2.h>
#include <C_CkSecureString.h>
#include <C_CkRest.h>
void ChilkatSample(void)
{
BOOL success;
HCkJsonObject json;
HCkCrypt2 crypt;
HCkSecureString ssLogin;
HCkSecureString ssPassword;
HCkRest rest;
BOOL bTls;
int port;
BOOL bAutoReconnect;
const char *responseJson;
success = FALSE;
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// Imagine we've previously saved our encrypted login and password within a JSON config file
// that contains this:
// {
// "http_login": "mCrOmA7mBA7Au9RuJGb9hw==",
// "http_password": "jJtiI9TgErTTpqBz9JtHBw=="
// }
json = CkJsonObject_Create();
CkJsonObject_LoadFile(json,"qa_data/passwords/http.json");
crypt = CkCrypt2_Create();
// These are the encryption settings we previously used to encrypt the credentials within the JSON config file.
CkCrypt2_putCryptAlgorithm(crypt,"aes");
CkCrypt2_putCipherMode(crypt,"cbc");
CkCrypt2_putKeyLength(crypt,128);
CkCrypt2_SetEncodedKey(crypt,"000102030405060708090A0B0C0D0E0F","hex");
CkCrypt2_SetEncodedIV(crypt,"000102030405060708090A0B0C0D0E0F","hex");
CkCrypt2_putEncodingMode(crypt,"base64");
ssLogin = CkSecureString_Create();
ssPassword = CkSecureString_Create();
// Decrypt to the secure string. (the strings will still held in memory encrypted, but are now encrypted using
// a randomly generated session key.)
CkCrypt2_DecryptSecureENC(crypt,CkJsonObject_stringOf(json,"http_login"),ssLogin);
CkCrypt2_DecryptSecureENC(crypt,CkJsonObject_stringOf(json,"http_password"),ssPassword);
rest = CkRest_Create();
// Connect to a REST server.
bTls = TRUE;
port = 443;
bAutoReconnect = TRUE;
success = CkRest_Connect(rest,"chilkatsoft.com",port,bTls,bAutoReconnect);
// Cause the "Authorization: Basic ..." header to be added to HTTP requests
CkRest_SetAuthBasicSecure(rest,ssLogin,ssPassword);
responseJson = CkRest_fullRequestNoBody(rest,"GET","/helloWorld.html");
if (CkRest_getLastMethodSuccess(rest) != TRUE) {
printf("%s\n",CkRest_lastErrorText(rest));
CkJsonObject_Dispose(json);
CkCrypt2_Dispose(crypt);
CkSecureString_Dispose(ssLogin);
CkSecureString_Dispose(ssPassword);
CkRest_Dispose(rest);
return;
}
// Show the LastRequestHeader that was sent.
printf("%s\n",CkRest_lastRequestHeader(rest));
// The LastRequestHeader looks like this:
// Host: chilkatsoft.com
// Authorization: Basic bXlIdHRwTG9naW46bXlIdHRwUGFzc3dvcmQ=
CkJsonObject_Dispose(json);
CkCrypt2_Dispose(crypt);
CkSecureString_Dispose(ssLogin);
CkSecureString_Dispose(ssPassword);
CkRest_Dispose(rest);
}