PowerBuilder
PowerBuilder
Xero 2 Legged OAuth for Private Application
This example demonstrates the REST object for 2-legged OAuth for a private application.An application can setup OAuth1 for a given instance of the Chilkat REST object, and then use the instance for many REST API calls. This example demonstrates the OAuth1 setup and initial connection. This code would typically be placed in a subroutine/function to "initalize" the REST object before beginning to use it for REST HTTP requests.
Note: Xero private applications use 2 legged OAuth and bypass the user authorization workflow in the standard OAuth process. Private applications are linked to a single Xero organisation which is chosen when you register your application. In summary: 2-legged OAuth1 is for applications that access the data that they themselves own.
Chilkat PowerBuilder Downloads
integer li_rc
integer li_Success
oleobject loo_Rest
string ls_ConsumerKey
string ls_ConsumerSecret
oleobject loo_Pfx
oleobject loo_PrivKeyFromPfx
oleobject loo_PrivKeyFromPem
oleobject loo_Oauth1
integer li_BAutoReconnect
li_Success = 0
// This sample code would typically be placed in a subroutine or function
// where the rest object is passed by reference.
// It does the OAuth1 setup and makes the initial connection.
loo_Rest = create oleobject
li_rc = loo_Rest.ConnectToNewObject("Chilkat.Rest")
if li_rc < 0 then
destroy loo_Rest
MessageBox("Error","Connecting to COM object failed")
return
end if
ls_ConsumerKey = "XERO_PRIVATE_APP_KEY"
ls_ConsumerSecret = "XERO_PRIVATE_APP_SECRET"
// Let's get our private key from our PFX (password protected), or the PEM (unprotected).
// You can decide which to use. Either is OK, although I would recommend keeping your
// private keys in a PFX and not in an unprotected PEM.
loo_Pfx = create oleobject
li_rc = loo_Pfx.ConnectToNewObject("Chilkat.Pfx")
li_Success = loo_Pfx.LoadPfxFile("qa_data/certs/xero_private_app/public_privatekey.pfx","PFX_PASSWORD")
if li_Success = 0 then
Write-Debug loo_Pfx.LastErrorText
destroy loo_Rest
destroy loo_Pfx
return
end if
loo_PrivKeyFromPfx = create oleobject
li_rc = loo_PrivKeyFromPfx.ConnectToNewObject("Chilkat.PrivateKey")
li_Success = loo_Pfx.PrivateKeyAt(0,loo_PrivKeyFromPfx)
if li_Success = 0 then
Write-Debug loo_Pfx.LastErrorText
destroy loo_Rest
destroy loo_Pfx
destroy loo_PrivKeyFromPfx
return
end if
// Or we can load from a PEM..
loo_PrivKeyFromPem = create oleobject
li_rc = loo_PrivKeyFromPem.ConnectToNewObject("Chilkat.PrivateKey")
li_Success = loo_PrivKeyFromPem.LoadPemFile("qa_data/certs/xero_private_app/privatekey.pem")
if li_Success = 0 then
Write-Debug loo_PrivKeyFromPem.LastErrorText
destroy loo_Rest
destroy loo_Pfx
destroy loo_PrivKeyFromPfx
destroy loo_PrivKeyFromPem
return
end if
// Note: There are many other means for loading a private key, including
// from other formats and directly from memory (i.e. not file-based).
loo_Oauth1 = create oleobject
li_rc = loo_Oauth1.ConnectToNewObject("Chilkat.OAuth1")
loo_Oauth1.ConsumerKey = ls_ConsumerKey
loo_Oauth1.ConsumerSecret = ls_ConsumerSecret
loo_Oauth1.Token = ls_ConsumerKey
loo_Oauth1.TokenSecret = ls_ConsumerSecret
loo_Oauth1.SignatureMethod = "RSA-SHA1"
loo_Oauth1.SetRsaKey(loo_PrivKeyFromPfx)
// Make the initial connection.
// A single REST object, once connected, can be used for many Xero REST API calls.
// The auto-reconnect indicates that if the already-established HTTPS connection is closed,
// then it will be automatically re-established as needed.
li_BAutoReconnect = 1
li_Success = loo_Rest.Connect("api.xero.com",443,1,li_BAutoReconnect)
if li_Success = 0 then
Write-Debug loo_Rest.LastErrorText
destroy loo_Rest
destroy loo_Pfx
destroy loo_PrivKeyFromPfx
destroy loo_PrivKeyFromPem
destroy loo_Oauth1
return
end if
// Finally, install the OAuth1 authenticator.
// (It make no difference whether this happens before or after the
// connection is established.)
loo_Rest.SetAuthOAuth1(loo_Oauth1,0)
Write-Debug "OK, the Xero OAuth1 is initialized and the REST object is ready to make REST API calls.."
destroy loo_Rest
destroy loo_Pfx
destroy loo_PrivKeyFromPfx
destroy loo_PrivKeyFromPem
destroy loo_Oauth1