Sample code for 30+ languages & platforms
Tcl

Set JWE Additional Authenticated Data

See more JSON Web Encryption (JWE) Examples

Demonstrates Jwe.SetAad, which sets external Additional Authenticated Data (AAD) for a JWE being encrypted, encoding the supplied text with the given charset.

Background. AAD is integrity-protected but not encrypted, binding external context to the ciphertext. The same AAD must be supplied again when decrypting.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

set jwe [new_CkJwe]

#  Protected header: AES key-wrap with AES-256-GCM content encryption.
set header [new_CkJsonObject]

CkJsonObject_UpdateString $header "alg" "A256KW"
CkJsonObject_UpdateString $header "enc" "A256GCM"
set success [CkJwe_SetProtectedHeader $jwe $header]
if {$success == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    delete_CkJsonObject $header
    exit
}

#  The 256-bit key-wrapping key (base64) for recipient index 0.  In production, obtain the key from a
#  secure source rather than hard-coding it.
set base64Key "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU="
set success [CkJwe_SetWrappingKey $jwe 0 $base64Key "base64"]
if {$success == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    delete_CkJsonObject $header
    exit
}

#  Set external Additional Authenticated Data (AAD).  The AAD is integrity-protected but not
#  encrypted, and must be supplied again when decrypting.
set success [CkJwe_SetAad $jwe "context-info-v1" "utf-8"]
if {$success == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    delete_CkJsonObject $header
    exit
}

set sbContent [new_CkStringBuilder]

CkStringBuilder_Append $sbContent "This is the secret content."
set sbJwe [new_CkStringBuilder]

set success [CkJwe_EncryptSb $jwe $sbContent "utf-8" $sbJwe]
if {$success == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    delete_CkJsonObject $header
    delete_CkStringBuilder $sbContent
    delete_CkStringBuilder $sbJwe
    exit
}

puts [CkStringBuilder_getAsString $sbJwe]

delete_CkJwe $jwe
delete_CkJsonObject $header
delete_CkStringBuilder $sbContent
delete_CkStringBuilder $sbJwe