Sample code for 30+ languages & platforms
React Native Requires Chilkat v11.0.0+

Validate a .pkpass Archive

See more Digital Signatures Examples

Opens a .pkpass archive (which is just a .zip renamed to .pkpass) and validates the contents. The hashes in the manifest are compared with the computed hash values for each individual file. If all computed hash values match, then the signature is verified.

Chilkat React Native Downloads

React Native
import { BinData, Crypt2, JsonObject, StringBuilder, Zip, ZipEntry } from '@chilkat/react-native'

async function chilkatExample() {
  let success = false;

  // This example assumes the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  const crypt = new Crypt2();
  const zip = new Zip();

  success = true;
  try {
    await zip.openZipAsync('qa_data/pkpass/invalid.pkpass');
  } catch {
    success = false;
  }
  if (!success) {
    console.log(zip.lastErrorText);
    return;
  }

  // Get the contents of the manifest.json file, which contains something like this:

  // {
  //   "icon.png" : "0296b01347b3173e98438a003b0e88986340b2d8",
  //   "logo.png" : "25de09e2d3b01ce1fe00c2ca9a90a2be1aaa05cf",
  //   "icon@2x.png" : "5afd9585b08c65fdf105a90c8bd643407cba2787",
  //   "pass.json" : "145ea5a5db784fff485126c77ecf7a1fc2a88ee7",
  //   "strip@2x.png" : "468fa7bc93e6b55342b56fda09bdce7c829d7d46",
  //   "strip.png" : "736d01f84cb73d06e8a9932e43076d68f19461ff"
  // }

  const ent = new ZipEntry();
  success = zip.entryOf('manifest.json', ent);
  if (!success) {
    console.log(zip.lastErrorText);
    return;
  }

  // Get the exact content of the manifest.json for later signature verification.
  const bdManifest = new BinData();
  success = true;
  try {
    await ent.unzipToBdAsync(bdManifest);
  } catch {
    success = false;
  }

  const json = new JsonObject();
  json.emitCompact = false;
  json.load(await ent.unzipToStringAsync(0, 'utf-8'));
  console.log(json.emit());

  // For each file in the JSON, get the filename and hex hash value.
  crypt.encodingMode = 'hexlower';
  crypt.hashAlgorithm = 'sha1';

  let someHashesFailed = false;
  let filename = '';
  const sbHashHex = new StringBuilder();
  const bdFileData = new BinData();
  const numMembers = json.size;
  let i = 0;
  while (i < numMembers) {
    filename = json.nameAt(i);
    sbHashHex.clear();
    sbHashHex.append(json.stringAt(i));

    success = zip.entryOf(filename, ent);
    if (!success) {
      console.log(zip.lastErrorText);
      return;
    }

    // Get the data for this file.
    bdFileData.clear();
    success = true;
    try {
      await ent.unzipToBdAsync(bdFileData);
    } catch {
      success = false;
    }

    const computedHashHex = crypt.hashBdENC(bdFileData);
    if (!sbHashHex.contentsEqual(computedHashHex, false)) {
      console.log(`Computed hash does not match stored hash for ${filename}`);
      console.log(`  computed: ${computedHashHex}`);
      console.log(`  stored:   ${sbHashHex.getAsString()}`);
      someHashesFailed = true;
    } else {
      console.log(`hash verified for ${filename}(${computedHashHex})`);
    }

    i++;
  }

  if (someHashesFailed) {
    console.log('Some hashes failed.');
    return;
  }

  // Let's verify the signature..
  // First get the signature.
  success = zip.entryOf('signature', ent);
  if (!success) {
    console.log(zip.lastErrorText);
    return;
  }

  const bdSignature = new BinData();
  success = true;
  try {
    await ent.unzipToBdAsync(bdSignature);
  } catch {
    success = false;
  }

  // Show the contents of the signature in base64 encoding.
  console.log('Signature:');
  console.log(bdSignature.getEncoded('base64_mime'));
  console.log('----');

  // Verify the signature against the manifest.json
  crypt.encodingMode = 'base64';
  let verified = true;
  try {
    crypt.verifyBdENC(bdManifest, bdSignature.getEncoded('base64'));
  } catch {
    verified = false;
  }
  if (!verified) {
    console.log(crypt.lastErrorText);
  }

  console.log(`signature verified = ${verified}`);
}