Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Signing HTTP Messages

See more RSA Examples

Demonstrates how to sign HTTP messages per draft-cavage-http-signatures-10

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const b_crlf = true;
    const sb_public_key_pem = try chilkat.StringBuilder.init();
    defer sb_public_key_pem.deinit();
    sb_public_key_pem.appendLine("-----BEGIN PUBLIC KEY-----", b_crlf) catch {};
    sb_public_key_pem.appendLine("MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCFENGw33yGihy92pDjZQhl0C3", b_crlf) catch {};
    sb_public_key_pem.appendLine("6rPJj+CvfSC8+q28hxA161QFNUd13wuCTUcq0Qd2qsBe/2hFyc2DCJJg0h1L78+6", b_crlf) catch {};
    sb_public_key_pem.appendLine("Z4UMR7EOcpfdUE9Hf3m/hs+FUR45uBJeDK1HSFHD8bHKD6kv8FPGfJTotc+2xjJw", b_crlf) catch {};
    sb_public_key_pem.appendLine("oYi+1hqp1fIekaxsyQIDAQAB", b_crlf) catch {};
    sb_public_key_pem.appendLine("-----END PUBLIC KEY-----", b_crlf) catch {};

    const pub_key = try chilkat.PublicKey.init();
    defer pub_key.deinit();
    pub_key.loadFromString(try sb_public_key_pem.getAsString(alloc)) catch {};

    const sb_private_key_pem = try chilkat.StringBuilder.init();
    defer sb_private_key_pem.deinit();
    sb_private_key_pem.appendLine("-----BEGIN RSA PRIVATE KEY-----", b_crlf) catch {};
    sb_private_key_pem.appendLine("MIICXgIBAAKBgQDCFENGw33yGihy92pDjZQhl0C36rPJj+CvfSC8+q28hxA161QF", b_crlf) catch {};
    sb_private_key_pem.appendLine("NUd13wuCTUcq0Qd2qsBe/2hFyc2DCJJg0h1L78+6Z4UMR7EOcpfdUE9Hf3m/hs+F", b_crlf) catch {};
    sb_private_key_pem.appendLine("UR45uBJeDK1HSFHD8bHKD6kv8FPGfJTotc+2xjJwoYi+1hqp1fIekaxsyQIDAQAB", b_crlf) catch {};
    sb_private_key_pem.appendLine("AoGBAJR8ZkCUvx5kzv+utdl7T5MnordT1TvoXXJGXK7ZZ+UuvMNUCdN2QPc4sBiA", b_crlf) catch {};
    sb_private_key_pem.appendLine("QWvLw1cSKt5DsKZ8UETpYPy8pPYnnDEz2dDYiaew9+xEpubyeW2oH4Zx71wqBtOK", b_crlf) catch {};
    sb_private_key_pem.appendLine("kqwrXa/pzdpiucRRjk6vE6YY7EBBs/g7uanVpGibOVAEsqH1AkEA7DkjVH28WDUg", b_crlf) catch {};
    sb_private_key_pem.appendLine("f1nqvfn2Kj6CT7nIcE3jGJsZZ7zlZmBmHFDONMLUrXR/Zm3pR5m0tCmBqa5RK95u", b_crlf) catch {};
    sb_private_key_pem.appendLine("412jt1dPIwJBANJT3v8pnkth48bQo/fKel6uEYyboRtA5/uHuHkZ6FQF7OUkGogc", b_crlf) catch {};
    sb_private_key_pem.appendLine("mSJluOdc5t6hI1VsLn0QZEjQZMEOWr+wKSMCQQCC4kXJEsHAve77oP6HtG/IiEn7", b_crlf) catch {};
    sb_private_key_pem.appendLine("kpyUXRNvFsDE0czpJJBvL/aRFUJxuRK91jhjC68sA7NsKMGg5OXb5I5Jj36xAkEA", b_crlf) catch {};
    sb_private_key_pem.appendLine("gIT7aFOYBFwGgQAQkWNKLvySgKbAZRTeLBacpHMuQdl1DfdntvAyqpAZ0lY0RKmW", b_crlf) catch {};
    sb_private_key_pem.appendLine("G6aFKaqQfOXKCyWoUiVknQJAXrlgySFci/2ueKlIE1QqIiLSZ8V8OlpFLRnb1pzI", b_crlf) catch {};
    sb_private_key_pem.appendLine("7U1yQXnTAEFYM560yJlzUpOb1V4cScGd365tiSMvxLOvTA==", b_crlf) catch {};
    sb_private_key_pem.appendLine("-----END RSA PRIVATE KEY-----", b_crlf) catch {};

    const priv_key = try chilkat.PrivateKey.init();
    defer priv_key.deinit();
    priv_key.loadPem(try sb_private_key_pem.getAsString(alloc)) catch {};

    //    All examples use this request:
    //
    //    POST /foo?param=value&pet=dog HTTP/1.1
    //    Host: example.com
    //    Date: Sun, 05 Jan 2014 21:31:40 GMT
    //    Content-Type: application/json
    //    Digest: SHA-256=X48E9qOokqqrvdts8nOJRJN3OWDUoyWxBf7kbu9DBPE=
    //    Content-Length: 18
    //
    //    {"hello": "world"}

    // C.1.  Default Test
    //
    //    If a list of headers is not included, the date is the only header
    //    that is signed by default.  The string to sign would be:
    //
    //    date: Sun, 05 Jan 2014 21:31:40 GMT
    //
    //    The Authorization header would be:
    //
    //    Authorization: Signature keyId="Test",algorithm="rsa-sha256",
    //    signature="SjWJWbWN7i0wzBvtPl8rbASWz5xQW6mcJmn+ibttBqtifLN7Sazz
    //    6m79cNfwwb8DMJ5cou1s7uEGKKCs+FLEEaDV5lp7q25WqS+lavg7T8hc0GppauB
    //    6hbgEKTwblDHYGEtbGmtdHgVCk9SuS13F0hZ8FD0k/5OxEPXe5WozsbM="
    //
    //    The Signature header would be:
    //
    //    Signature: keyId="Test",algorithm="rsa-sha256",
    //    signature="SjWJWbWN7i0wzBvtPl8rbASWz5xQW6mcJmn+ibttBqtifLN7Sazz
    //    6m79cNfwwb8DMJ5cou1s7uEGKKCs+FLEEaDV5lp7q25WqS+lavg7T8hc0GppauB
    //    6hbgEKTwblDHYGEtbGmtdHgVCk9SuS13F0hZ8FD0k/5OxEPXe5WozsbM="
    //

    const dt_now = try chilkat.DateTime.init();
    defer dt_now.deinit();
    try dt_now.setFromCurrentSystemTime();
    var date_str: [:0]const u8 = try dt_now.getAsRfc822(alloc, false);

    // To duplicate the above result, we'll hard-code the date string.
    date_str = "Sun, 05 Jan 2014 21:31:40 GMT";

    const rsa = try chilkat.Rsa.init();
    defer rsa.deinit();
    rsa.usePrivateKey(priv_key) catch {
        std.debug.print("{s}\n", .{try rsa.getLastErrorText(alloc)});
        return;
    };

    const sb_string_to_sign = try chilkat.StringBuilder.init();
    defer sb_string_to_sign.deinit();
    sb_string_to_sign.append("date: ") catch {};
    sb_string_to_sign.append(date_str) catch {};

    rsa.setEncodingMode("base64");
    var b64_signature: [:0]const u8 = try rsa.signStringENC(alloc, try sb_string_to_sign.getAsString(alloc), "SHA256");
    std.debug.print("{s}\n", .{b64_signature});
    std.debug.print("---------------------------\n", .{});

    // The result should be:
    // SjWJWbWN7i0wzBvtPl8rbASW ... FD0k/5OxEPXe5WozsbM=

    // ----------------------------------------------------------------------------------------------------

    // C.2.  Basic Test
    //
    //    The minimum recommended data to sign is the (request-target), host,
    //    and date.  In this case, the string to sign would be:
    //
    //    (request-target): post /foo?param=value&pet=dog
    //    host: example.com
    //    date: Sun, 05 Jan 2014 21:31:40 GMT
    //
    //    The Authorization header would be:
    //
    //    Authorization: Signature keyId="Test",algorithm="rsa-sha256",
    //    headers="(request-target) host date", signature="qdx+H7PHHDZgy4
    //    y/Ahn9Tny9V3GP6YgBPyUXMmoxWtLbHpUnXS2mg2+SbrQDMCJypxBLSPQR2aAjn
    //    7ndmw2iicw3HMbe8VfEdKFYRqzic+efkb3nndiv/x1xSHDJWeSWkx3ButlYSuBs
    //    kLu6kd9Fswtemr3lgdDEmn04swr2Os0="

    sb_string_to_sign.clear();
    sb_string_to_sign.append("(request-target): ") catch {};
    sb_string_to_sign.appendLine("post /foo?param=value&pet=dog", false) catch {};
    sb_string_to_sign.append("host: ") catch {};
    sb_string_to_sign.appendLine("example.com", false) catch {};
    sb_string_to_sign.append("date: ") catch {};
    sb_string_to_sign.append(date_str) catch {};

    std.debug.print("StringToSign:\n", .{});
    std.debug.print("{s}\n", .{try sb_string_to_sign.getAsString(alloc)});
    b64_signature = try rsa.signStringENC(alloc, try sb_string_to_sign.getAsString(alloc), "SHA256");
    std.debug.print("{s}\n", .{b64_signature});
    std.debug.print("---------------------------\n", .{});

    // The result should be:
    // qdx+H7PHHDZgy4y/Ahn ... mn04swr2Os0=
}