Sample code for 30+ languages & platforms
Zig

ITIDA Debug Signed JSON and HTTP POST

See more Egypt ITIDA Examples

Explains how to debug when problems are encountered with ITIDA canonicalization, signing, and posting to api.preprod.invoicing.eta.gov.eg.

The most common error response from the api.preprod.invoicing.eta.gov.eg server is:

ITIDA Signature Invalid Signature * 4043 4043:message-digest attribute value does not match the calculated value[message-digest attribute value does not match the calculated value]

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example assumes the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();
    crypt.setVerboseLogging(true);

    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    cert.setVerboseLogging(true);

    // Set the smart card PIN, which will be needed for signing.
    cert.setSmartCardPin("12345678");

    // There are many ways to load the certificate.
    // This example was created for a customer using an ePass2003 USB token.
    // Assuming the USB token is the only source of a hardware-based private key..
    cert.loadFromSmartcard("") catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    // Tell the crypt class to use this cert.
    crypt.setSigningCert(cert) catch {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
        return;
    };

    const cms_options = try chilkat.JsonObject.init();
    defer cms_options.deinit();
    // Setting "DigestData" causes OID 1.2.840.113549.1.7.5 (digestData) to be used.
    cms_options.updateBool("DigestData", true) catch {};
    cms_options.updateBool("OmitAlgorithmIdNull", true) catch {};

    // Indicate that we are passing normal JSON and we want Chilkat do automatically
    // do the ITIDA JSON canonicalization:
    cms_options.updateBool("CanonicalizeITIDA", true) catch {};

    crypt.setCmsOptions(try cms_options.emit(alloc));

    // The CadesEnabled property applies to all methods that create CMS/PKCS7 signatures.
    // To create a CAdES-BES signature, set this property equal to true.
    crypt.setCadesEnabled(true);

    crypt.setHashAlgorithm("sha256");

    const json_signing_attrs = try chilkat.JsonObject.init();
    defer json_signing_attrs.deinit();
    json_signing_attrs.updateInt("contentType", 1) catch {};
    json_signing_attrs.updateInt("signingTime", 1) catch {};
    json_signing_attrs.updateInt("messageDigest", 1) catch {};
    json_signing_attrs.updateInt("signingCertificateV2", 1) catch {};
    crypt.setSigningAttributes(try json_signing_attrs.emit(alloc));

    // By default, all the certs in the chain of authentication are included in the signature.
    // If desired, we can choose to only include the signing certificate:
    crypt.setIncludeCertChain(false);

    // First, load the JSON file that is to be canonicalized and signed.
    // The JSON file should look like this:
    // NOTE: The JSON should not begin with "{ "documents" : [ ..."
    // We want to send a single signed document like this:

    //       {
    //          "issuer":{
    //             "address":{
    //                "branchID":"0",
    //                "country":"EG",
    //                "regionCity":"Cairo",
    //                "postalCode":"",
    //                "buildingNumber":"0",
    //                "street":"123rd Street",
    //                "governate":"GOVERNATE"
    //             },
    //             "type":"B",
    //             "id":"209999899",
    //             "name":"Xyz SAE"
    //          },
    //          "receiver":{
    //             "address":{
    //                "country":"EG",
    //                "regionCity":"CAIRO",
    //                "postalCode":"11435",
    //                "buildingNumber":"0",
    //                "street":"Autostrad Road Abc",
    //                "governate":"GOVERNATE"
    //             },
    //             "type":"B",
    //             "id":"999999999",
    //             "name":"XYZ EGYPT FOR TRADE"
    //          },
    //          "documentType":"I",
    //          "documentTypeVersion":"1.0",
    //          "dateTimeIssued":"2020-11-15T11:04:53Z",
    //          "taxpayerActivityCode":"1073",
    //          "internalID":"ZZZZ999",
    //          "purchaseOrderReference":"2009199918",
    //          "salesOrderReference":"",
    //          "payment":{
    //             "bankName":"",
    //             "bankAddress":"",
    //             "bankAccountNo":"",
    //             "bankAccountIBAN":"",
    //             "swiftCode":"",
    //             "terms":""
    //          },
    //          "delivery":{
    //             "approach":"",
    //             "packaging":"",
    //             "dateValidity":"",
    //             "exportPort":"",
    //             "countryOfOrigin":"EG",
    //             "grossWeight":0,
    //             "netWeight":0,
    //             "terms":""
    //          },
    //          "invoiceLines":[
    //             {
    //                "description":"CDM Widget 48GX99X12BA",
    //                "itemType":"GS1",
    //                "itemCode":"7622213335056",
    //                "unitType":"CS",
    //                "quantity":1.00,
    //                "unitValue":{
    //                   "currencySold":"EGP",
    //                   "amountEGP":588.67,
    //                   "amountSold":0,
    //                   "currencyExchangeRate":0
    //                },
    //                "salesTotal":588.67,
    //                "total":603.97,
    //                "valueDifference":0,
    //                "totalTaxableFees":0,
    //                "netTotal":529.8,
    //                "itemsDiscount":0,
    //                "discount":{
    //                   "rate":10.00,
    //                   "amount":58.87
    //                },
    //                "taxableItems":[
    //                   {
    //                      "taxType":"T1",
    //                      "amount":74.17,
    //                      "subType":"No sub",
    //                      "rate":14.00
    //                   }
    //                ],
    //                "internalCode":"9099994"
    //             }
    //          ],
    //          "totalSales":588.67,
    //          "totalSalesAmount":588.67,
    //          "totalDiscountAmount":58.87,
    //          "netAmount":529.80,
    //          "taxTotals":[
    //             {
    //                "taxType":"T1",
    //                "amount":74.17
    //             }
    //          ],
    //          "extraDiscountAmount":0,
    //          "totalItemsDiscountAmount":0,
    //          "totalAmount":603.97,
    //       }
    //

    // Please include this JSON file as an attachment in your support email to Chilkat.
    const json = try chilkat.JsonObject.init();
    defer json.deinit();
    json.loadFile("c:/someDir/jsonToSignAndSend.json") catch {
        std.debug.print("Failed to load input JSON file.\n", .{});
        return;
    };

    json.setEmitCompact(true);
    const json_to_sign = try json.emit(alloc);

    // Create the CAdES-BES signature.
    crypt.setEncodingMode("base64");

    // Make sure we sign the utf-8 byte representation of the JSON string
    crypt.setCharset("utf-8");

    // Turn on verbose logging.
    crypt.setVerboseLogging(true);

    const sig_base64 = crypt.signStringENC(alloc, json_to_sign) catch {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
        return;
    };

    // The LastErrorText property still contains information when the method succeeds.
    // Send the contents of this LastErrorText as an attachment in your support email to Chilkat.
    std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});

    // Insert the base64 signature into the JSON to be sent
    json.updateString("signatures[0].signatureType", "I") catch {};
    json.updateString("signatures[0].value", sig_base64) catch {};

    // Wrap the JSON in  {"documents":[ ... ]}
    const sb_to_send = try chilkat.StringBuilder.init();
    defer sb_to_send.deinit();
    sb_to_send.append("{\"documents\":[") catch {};
    sb_to_send.append(try json.emit(alloc)) catch {};
    sb_to_send.append("]}") catch {};

    // ------------------------------------------------------------------------
    // Submit the signed JSON to Chilkat's URL for simply echoing back the contents of the HTTP POST it receives:
    //
    // We just want to see what actually gets sent.  To do this, we can send to https://www.chilkatsoft.com/echoPostBody.asp
    // which will echo in the response that data and headers it received.

    const http = try chilkat.Http.init();
    defer http.deinit();

    // Also, set the SessionLogFilename property so we can see the exact bytes of the HTTP request sent from your end.
    // Please include this session log file as an attachment in your support email to Chilkat.
    http.setSessionLogFilename("c:/someDir/sessionLog.txt");

    const json_str = try sb_to_send.getAsString(alloc);
    const resp = try chilkat.HttpResponse.init();
    defer resp.deinit();
    http.httpStr("POST", "https://www.chilkatsoft.com/echoPostBody.asp", json_str, "utf-8", "application/json; charset=utf-8", resp) catch {
        std.debug.print("{s}\n", .{try http.getLastErrorText(alloc)});
        return;
    };

    // Save the exact contents of Chilkat's response to a file.
    // The server at https://www.chilkatsoft.com/echoPostBody.asp is simply echoing back the headers and POST body it received.
    // Please include the responseBody.txt as an attachment in your support email to Chilkat.
    try resp.saveBodyBinary("c:/someDir/responseBody.txt");

    std.debug.print("Response status code: {d}\n", .{resp.getStatusCode()});

    // -------------------------------------------------
    // In summary, please include the following in your support email to Chilkat
    // 1. The original JSON file before signing and before canonicalization (i.e. c:/someDir/jsonToSignAndSend.json)
    // 2. The contents of the LastErrorText for the successful call to SignStringENC.
    // 3. The HTTP session log file (i.e. c:/someDir/sessionLog.txt)
    // 4. The responseBody.txt file.
}