Sample code for 30+ languages & platforms
Zig

JWE using AES Key Wrap and AES_128_CBC_HMAC_SHA_256

See more JSON Web Encryption (JWE) Examples

This example duplicates the example A.3 in RFC 7516 for JSON Web Encryption (JWE).

Note: This example requires Chilkat v9.5.0.66 or greater.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // Note: This example requires Chilkat v9.5.0.66 or greater.

    const plaintext = "Live long and prosper.";

    const jwe = try chilkat.Jwe.init();
    defer jwe.deinit();

    // First build the JWE Protected Header: {"alg":"A128KW","enc":"A128CBC-HS256"}
    const jwe_prot_hdr = try chilkat.JsonObject.init();
    defer jwe_prot_hdr.deinit();
    jwe_prot_hdr.appendString("alg", "A128KW") catch {};
    jwe_prot_hdr.appendString("enc", "A128CBC-HS256") catch {};
    jwe.setProtectedHeader(jwe_prot_hdr) catch {};

    std.debug.print("JWE Protected Header: {s}\n", .{try jwe_prot_hdr.emit(alloc)});
    std.debug.print("--\n", .{});

    // The example A.3 in RFC 7516 uses the following 128-bit AES key,
    // specified in JWK (JSON Web Key) format:
    //      {"kty":"oct",
    //       "k":"GawgguFyGrWKav7AX4VKUg"
    //      }
    // This is just a way of saying: The key type ("kty") is
    // a bunch of octets ("k") in base64url encoding.
    // We can simply set the AES wrapping key like this:
    const aes_wrapping_key = "GawgguFyGrWKav7AX4VKUg";
    jwe.setWrappingKey(0, aes_wrapping_key, "base64url") catch {};

    // Encrypt and return the JWE:
    const str_jwe = jwe.encrypt(alloc, plaintext, "utf-8") catch {
        std.debug.print("{s}\n", .{try jwe.getLastErrorText(alloc)});
        return;
    };

    // Show the JWE we just created:
    std.debug.print("{s}\n", .{str_jwe});

    // Decrypt the JWE that was just produced.
    // 1) Load the JWE.
    // 2) Set the AES wrapping key.
    // 3) Decrypt.
    const jwe2 = try chilkat.Jwe.init();
    defer jwe2.deinit();
    jwe2.loadJwe(str_jwe) catch {
        std.debug.print("{s}\n", .{try jwe2.getLastErrorText(alloc)});
        return;
    };

    // Set the AES wrap key.
    jwe2.setWrappingKey(0, aes_wrapping_key, "base64url") catch {};

    // Decrypt.
    var original_plaintext: [:0]const u8 = jwe2.decrypt(alloc, 0, "utf-8") catch {
        std.debug.print("{s}\n", .{try jwe2.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("original text: \n", .{});
    std.debug.print("{s}\n", .{original_plaintext});

    // ---------------------------------------------------------------------------------
    // It should also be possible to decrypt the JWE as shown in RFC 7516, Appendix A.3.7
    // because it was produced using the same AES Wrap key.

    const sb_jwe = try chilkat.StringBuilder.init();
    defer sb_jwe.deinit();
    sb_jwe.append("eyJhbGciOiJBMTI4S1ciLCJlbmMiOiJBMTI4Q0JDLUhTMjU2In0.") catch {};
    sb_jwe.append("6KB707dM9YTIgHtLvtgWQ8mKwboJW3of9locizkDTHzBC2IlrT1oOQ.") catch {};
    sb_jwe.append("AxY8DCtDaGlsbGljb3RoZQ.") catch {};
    sb_jwe.append("KDlTtXchhZTGufMYmOYGS4HffxPSUrfmqCHXaI9wOGY.") catch {};
    sb_jwe.append("U0m_YmjN04DJvceFICbCVQ") catch {};

    jwe2.loadJweSb(sb_jwe) catch {
        std.debug.print("{s}\n", .{try jwe2.getLastErrorText(alloc)});
        return;
    };

    jwe2.setWrappingKey(0, aes_wrapping_key, "base64url") catch {};

    // Decrypt.
    original_plaintext = jwe2.decrypt(alloc, 0, "utf-8") catch {
        std.debug.print("{s}\n", .{try jwe2.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("{s}\n", .{original_plaintext});
}