Sample code for 30+ languages & platforms
Zig

Create JPK_VAT XaDES-BES Signed XML

See more XAdES Examples

Demonstrates how to sign XML for JPK_VAT.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // This example will sign the following XML document:

    // <?xml version="1.0" encoding="utf-8"?>
    // <InitUpload xmlns="http://e-dokumenty.mf.gov.pl">
    //     <DocumentType>JPK</DocumentType>
    //     <Version>01.02.01.20160617</Version>
    //     <EncryptionKey algorithm="RSA" encoding="Base64" mode="ECB" padding="PKCS#1">...</EncryptionKey>
    //     <DocumentList>
    //         <Document>
    //             <FormCode schemaVersion="1-1" systemCode="JPK_VAT (3)">JPK_VAT</FormCode>
    //             <FileName>JPK_VAT_3_v1-1_20181208.xml</FileName>
    //             <ContentLength>8736</ContentLength>
    //             <HashValue algorithm="SHA-256" encoding="Base64">JEEI1pItwh6dj/Xe1uts/x61qnjZ4DLHpkRMhmf1oQQ=</HashValue>
    //             <FileSignatureList filesNumber="1">
    //                 <Packaging>
    //                     <SplitZip mode="zip" type="split"/>
    //                 </Packaging>
    //                 <Encryption>
    //                     <AES block="16" mode="CBC" padding="PKCS#7" size="256">
    //                         <IV bytes="16" encoding="Base64">FFsCRAPYJD3J6cRvd44UDA==</IV>
    //                     </AES>
    //                 </Encryption>
    //                 <FileSignature>
    //                     <OrdinalNumber>1</OrdinalNumber>
    //                     <FileName>JPK_VAT_3_v1-1_20181208-000.xml.zip.aes</FileName>
    //                     <ContentLength>16</ContentLength>
    //                     <HashValue algorithm="MD5" encoding="Base64">BX2DTD3ASC/zF6aq/012Cg==</HashValue>
    //                 </FileSignature>
    //             </FileSignatureList>
    //         </Document>
    //     </DocumentList>
    // </InitUpload>

    // First we build the XML to be signed.
    //
    // Use this online tool to generate the code from sample XML:
    // Generate Code to Create XML

    const xml_to_sign = try chilkat.Xml.init();
    defer xml_to_sign.deinit();
    xml_to_sign.setTag("InitUpload");
    xml_to_sign.addAttribute("xmlns", "http://e-dokumenty.mf.gov.pl") catch {};
    xml_to_sign.updateChildContent("DocumentType", "JPK");
    xml_to_sign.updateChildContent("Version", "01.02.01.20160617");
    xml_to_sign.updateAttrAt("EncryptionKey", true, "algorithm", "RSA") catch {};
    xml_to_sign.updateAttrAt("EncryptionKey", true, "encoding", "Base64") catch {};
    xml_to_sign.updateAttrAt("EncryptionKey", true, "mode", "ECB") catch {};
    xml_to_sign.updateAttrAt("EncryptionKey", true, "padding", "PKCS#1") catch {};
    xml_to_sign.updateChildContent("EncryptionKey", "...");
    xml_to_sign.updateAttrAt("DocumentList|Document|FormCode", true, "schemaVersion", "1-1") catch {};
    xml_to_sign.updateAttrAt("DocumentList|Document|FormCode", true, "systemCode", "JPK_VAT (3)") catch {};
    xml_to_sign.updateChildContent("DocumentList|Document|FormCode", "JPK_VAT");
    xml_to_sign.updateChildContent("DocumentList|Document|FileName", "JPK_VAT_3_v1-1_20181208.xml");
    xml_to_sign.updateChildContent("DocumentList|Document|ContentLength", "8736");
    xml_to_sign.updateAttrAt("DocumentList|Document|HashValue", true, "algorithm", "SHA-256") catch {};
    xml_to_sign.updateAttrAt("DocumentList|Document|HashValue", true, "encoding", "Base64") catch {};
    xml_to_sign.updateChildContent("DocumentList|Document|HashValue", "JEEI1pItwh6dj/Xe1uts/x61qnjZ4DLHpkRMhmf1oQQ=");
    xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList", true, "filesNumber", "1") catch {};
    xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Packaging|SplitZip", true, "mode", "zip") catch {};
    xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Packaging|SplitZip", true, "type", "split") catch {};
    xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "block", "16") catch {};
    xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "mode", "CBC") catch {};
    xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "padding", "PKCS#7") catch {};
    xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "size", "256") catch {};
    xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES|IV", true, "bytes", "16") catch {};
    xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES|IV", true, "encoding", "Base64") catch {};
    xml_to_sign.updateChildContent("DocumentList|Document|FileSignatureList|Encryption|AES|IV", "FFsCRAPYJD3J6cRvd44UDA==");
    xml_to_sign.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|OrdinalNumber", "1");
    xml_to_sign.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|FileName", "JPK_VAT_3_v1-1_20181208-000.xml.zip.aes");
    xml_to_sign.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|ContentLength", "16");
    xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|FileSignature|HashValue", true, "algorithm", "MD5") catch {};
    xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|FileSignature|HashValue", true, "encoding", "Base64") catch {};
    xml_to_sign.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|HashValue", "BX2DTD3ASC/zF6aq/012Cg==");

    // Also see the online tool to generate the code from sample already-signed XML:
    // Generate XML Signature Creation Code from an Already-Signed XML Sample

    const gen = try chilkat.XmlDSigGen.init();
    defer gen.deinit();

    gen.setSigLocation("InitUpload");
    gen.setSigId("id-1234");
    gen.setSigNamespacePrefix("ds");
    gen.setSigNamespaceUri("http://www.w3.org/2000/09/xmldsig#");
    gen.setSignedInfoCanonAlg("EXCL_C14N");
    gen.setSignedInfoDigestMethod("sha256");

    // Create an Object to be added to the Signature.
    const object1 = try chilkat.Xml.init();
    defer object1.deinit();
    object1.setTag("xades:QualifyingProperties");
    object1.addAttribute("Target", "#id-1234") catch {};
    object1.addAttribute("xmlns:xades", "http://uri.etsi.org/01903/v1.3.2#") catch {};
    object1.updateAttrAt("xades:SignedProperties", true, "Id", "xades-id-1234") catch {};
    object1.updateChildContent("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningTime", "TO BE GENERATED BY CHILKAT");
    object1.updateAttrAt("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningCertificateV2|xades:Cert|xades:CertDigest|ds:DigestMethod", true, "Algorithm", "http://www.w3.org/2001/04/xmlenc#sha256") catch {};
    object1.updateChildContent("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningCertificateV2|xades:Cert|xades:CertDigest|ds:DigestValue", "TO BE GENERATED BY CHILKAT");
    object1.updateChildContent("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningCertificateV2|xades:Cert|xades:IssuerSerialV2", "TO BE GENERATED BY CHILKAT");
    object1.updateAttrAt("xades:SignedProperties|xades:SignedDataObjectProperties|xades:DataObjectFormat", true, "ObjectReference", "#r-id-1") catch {};
    object1.updateChildContent("xades:SignedProperties|xades:SignedDataObjectProperties|xades:DataObjectFormat|xades:MimeType", "text/xml");

    gen.addObject("", try object1.getXml(alloc), "", "") catch {};

    // -------- Reference 1 --------
    const xml1 = try chilkat.Xml.init();
    defer xml1.deinit();
    xml1.setTag("ds:Transforms");
    xml1.updateAttrAt("ds:Transform", true, "Algorithm", "http://www.w3.org/TR/1999/REC-xpath-19991116") catch {};
    xml1.updateChildContent("ds:Transform|ds:XPath", "not(ancestor-or-self::ds:Signature)");
    xml1.updateAttrAt("ds:Transform[1]", true, "Algorithm", "http://www.w3.org/2001/10/xml-exc-c14n#") catch {};

    gen.addSameDocRef2("", "sha256", xml1, "") catch {};
    gen.setRefIdAttr("", "r-id-1") catch {};

    // -------- Reference 2 --------
    const xml2 = try chilkat.Xml.init();
    defer xml2.deinit();
    xml2.setTag("ds:Transforms");
    xml2.updateAttrAt("ds:Transform", true, "Algorithm", "http://www.w3.org/2001/10/xml-exc-c14n#") catch {};

    gen.addObjectRef2("xades-id-1234", "sha256", xml2, "http://uri.etsi.org/01903#SignedProperties") catch {};

    // Provide a certificate + private key. (PFX password is test123)
    // See Load Certificate on Smartcard for an example showing how to load the cert from a smartcard..
    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    cert.loadPfxFile("qa_data/pfx/cert_test123.pfx", "test123") catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    gen.setX509Cert(cert, true) catch {};

    gen.setKeyInfoType("X509Data");
    gen.setX509Type("Certificate");

    // Load XML to be signed...
    const sb_xml = try chilkat.StringBuilder.init();
    defer sb_xml.deinit();
    xml_to_sign.getXmlSb(sb_xml) catch {};

    gen.setBehaviors("IndentedSignature,TransformSignatureXPath,IssuerSerialHex");

    // Sign the XML...
    gen.createXmlDSigSb(sb_xml) catch {
        std.debug.print("{s}\n", .{try gen.getLastErrorText(alloc)});
        return;
    };

    // Save the signed XMl to a file.
    try sb_xml.writeFile("qa_output/signedXml.xml", "utf-8", false);

    std.debug.print("{s}\n", .{try sb_xml.getAsString(alloc)});

    // ----------------------------------------
    // Verify the signature we just produced...
    const verifier = try chilkat.XmlDSig.init();
    defer verifier.deinit();
    verifier.loadSignatureSb(sb_xml) catch {
        std.debug.print("{s}\n", .{try verifier.getLastErrorText(alloc)});
        return;
    };

    verifier.verifySignature(true) catch {
        std.debug.print("{s}\n", .{try verifier.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("This signature was successfully verified.\n", .{});
}