Node.js
Node.js
Set the Optional JWS Unprotected Header
See more JSON Web Signatures (JWS) Examples
Demonstrates Jws.SetUnprotectedHeader, which sets the optional unprotected header for a signature.
Background. Unlike the protected header, the unprotected header is not covered by the signature. It is carried in the JSON serialization forms of a JWS, so producing a JWS with an unprotected header yields a JSON serialization rather than compact form.
Chilkat Node.js Downloads
NODEJS_PRELUDE
function chilkatExample() {
var success = false;
var jws = new chilkat.Jws();
// Protected header specifying HMAC-SHA256.
var header = new chilkat.JsonObject();
header.UpdateString("alg","HS256");
success = jws.SetProtectedHeader(0,header);
if (success == false) {
console.log(jws.LastErrorText);
return;
}
// Set the optional unprotected header for signature 0. Unlike the protected header, it is not
// covered by the signature. It is carried in the JSON serialization forms of a JWS.
var unprotected = new chilkat.JsonObject();
unprotected.UpdateString("kid","signer-key-1");
success = jws.SetUnprotectedHeader(0,unprotected);
if (success == false) {
console.log(jws.LastErrorText);
return;
}
var bIncludeBom = false;
success = jws.SetPayload("This is the content to sign.","utf-8",bIncludeBom);
if (success == false) {
console.log(jws.LastErrorText);
return;
}
var base64Key = "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU=";
success = jws.SetMacKey(0,base64Key,"base64");
if (success == false) {
console.log(jws.LastErrorText);
return;
}
// Because an unprotected header is present, the JWS is produced in a JSON serialization form.
var jwsJson = jws.CreateJws();
if (jws.LastMethodSuccess == false) {
console.log(jws.LastErrorText);
return;
}
console.log(jwsJson);
}
chilkatExample();