Tcl
Tcl
Decrypt a JWE into a StringBuilder
See more JSON Web Encryption (JWE) Examples
Demonstrates Jwe.DecryptSb, which decrypts a recipient of a loaded JWE and writes the plaintext into a StringBuilder.
Background. The recipient index selects which recipient's key material to use. The key for that recipient must be provided before decrypting.
Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
set jwe [new_CkJwe]
# Load the JWE compact serialization to be decrypted.
set jweCompact "eyJhbGciOiJBMjU2S1ciLCJlbmMiOiJBMjU2R0NNIn0.<...>.<iv>.<ciphertext>.<tag>"
set success [CkJwe_LoadJwe $jwe $jweCompact]
if {$success == 0} then {
puts [CkJwe_lastErrorText $jwe]
delete_CkJwe $jwe
exit
}
# The 256-bit key-wrapping key (base64) for recipient index 0. In production, obtain the key
# from a secure source rather than hard-coding it.
set base64Key "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU="
set success [CkJwe_SetWrappingKey $jwe 0 $base64Key "base64"]
if {$success == 0} then {
puts [CkJwe_lastErrorText $jwe]
delete_CkJwe $jwe
exit
}
# Decrypt recipient index 0, writing the plaintext into a StringBuilder.
set sbContent [new_CkStringBuilder]
set success [CkJwe_DecryptSb $jwe 0 "utf-8" $sbContent]
if {$success == 0} then {
puts [CkJwe_lastErrorText $jwe]
delete_CkJwe $jwe
delete_CkStringBuilder $sbContent
exit
}
puts [CkStringBuilder_getAsString $sbContent]
delete_CkJwe $jwe
delete_CkStringBuilder $sbContent