Sample code for 30+ languages & platforms
Xbase++

REST Basic Auth with Secure Strings

Demonstrates how to do REST Basic authentication using secure strings.

This example requires Chilkat v9.5.0.71 or greater.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oJson
LOCAL oCrypt
LOCAL oSsLogin
LOCAL oSsPassword
LOCAL oRest
LOCAL nBTls
LOCAL nPort
LOCAL nBAutoReconnect
LOCAL cResponseJson

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  Imagine we've previously saved our encrypted login and password within a JSON config file
//  that contains this:

//  {
//    "http_login": "mCrOmA7mBA7Au9RuJGb9hw==",
//    "http_password": "jJtiI9TgErTTpqBz9JtHBw=="
//  }

oJson := CreateObject("Chilkat.JsonObject")
oJson:LoadFile("qa_data/passwords/http.json")

oCrypt := CreateObject("Chilkat.Crypt2")

//  These are the encryption settings we previously used to encrypt the credentials within the JSON config file.
oCrypt:CryptAlgorithm := "aes"
oCrypt:CipherMode := "cbc"
oCrypt:KeyLength := 128
oCrypt:SetEncodedKey("000102030405060708090A0B0C0D0E0F", "hex")
oCrypt:SetEncodedIV("000102030405060708090A0B0C0D0E0F", "hex")
oCrypt:EncodingMode := "base64"

oSsLogin := CreateObject("Chilkat.SecureString")
oSsPassword := CreateObject("Chilkat.SecureString")

//  Decrypt to the secure string.  (the strings will still held in memory encrypted, but are now encrypted using
//  a randomly generated session key.)
oCrypt:DecryptSecureENC(oJson:StringOf("http_login"), oSsLogin)
oCrypt:DecryptSecureENC(oJson:StringOf("http_password"), oSsPassword)

oRest := CreateObject("Chilkat.Rest")

//  Connect to a REST server.
nBTls := 1
nPort := 443
nBAutoReconnect := 1
nSuccess := oRest:Connect("chilkatsoft.com", nPort, nBTls, nBAutoReconnect)

//  Cause the "Authorization: Basic ..." header to be added to HTTP requests
oRest:SetAuthBasicSecure(oSsLogin, oSsPassword)

cResponseJson := oRest:FullRequestNoBody("GET", "/helloWorld.html")
IF (oRest:LastMethodSuccess != 1)
    ? oRest:LastErrorText
    oJson:destroy()
    oCrypt:destroy()
    oSsLogin:destroy()
    oSsPassword:destroy()
    oRest:destroy()
    RETURN
ENDIF

//  Show the LastRequestHeader that was sent.
? oRest:LastRequestHeader

//  The LastRequestHeader looks like this:

//  Host: chilkatsoft.com
//  Authorization: Basic bXlIdHRwTG9naW46bXlIdHRwUGFzc3dvcmQ=

oJson:destroy()
oCrypt:destroy()
oSsLogin:destroy()
oSsPassword:destroy()
oRest:destroy()