Zig
Zig
XML-DSig Add Object Reference with Transforms Specified Explicitly
Demonstrates how to use the new AddObjectRef2 method to explicitly specify the XML Transforms fragment.Chilkat Zig Downloads
const std = @import("std");
const chilkat = @import("chilkat");
pub fn main(init: std.process.Init) !void {
const alloc = init.arena.allocator();
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// Build the following XML to be signed:
// <?xml version="1.0" encoding="utf-8"?>
// <InitUpload xmlns="http://e-dokumenty.mf.gov.pl">
// <DocumentType>JPK</DocumentType>
// <Version>01.02.01.20160617</Version>
// <EncryptionKey algorithm="RSA" encoding="Base64" mode="ECB" padding="PKCS#1">xxxx</EncryptionKey>
// <DocumentList>
// <Document>
// <FormCode schemaVersion="1-1" systemCode="JPK_VAT (3)">JPK_VAT</FormCode>
// <FileName>JPK_VAT_3_v1-1_20181201.xml</FileName>
// <ContentLength>8736</ContentLength>
// <HashValue algorithm="SHA-256" encoding="Base64">JEDI1pItwh6dj/Xx1uts/x61qnjZ4DLHpkZMhmf1oKQ=</HashValue>
// <FileSignatureList filesNumber="1">
// <Packaging>
// <SplitZip mode="zip" type="split"/>
// </Packaging>
// <Encryption>
// <AES block="16" mode="CBC" padding="PKCS#7" size="256">
// <IV bytes="16" encoding="Base64">z64oN9zXHt1+S3XACRSCYw==</IV>
// </AES>
// </Encryption>
// <FileSignature>
// <OrdinalNumber>1</OrdinalNumber>
// <FileName>JPK_VAT_3_v1-1_20181201-000.xml.zip.aes</FileName>
// <ContentLength>16</ContentLength>
// <HashValue algorithm="MD5" encoding="Base64">5MX0q1935fvMjLFV7E1yDw==</HashValue>
// </FileSignature>
// </FileSignatureList>
// </Document>
// </DocumentList>
// </InitUpload>
// Use this online tool to generate code from sample XML:
// Generate Code to Create XML
const xml_to_sign = try chilkat.Xml.init();
defer xml_to_sign.deinit();
xml_to_sign.setTag("InitUpload");
xml_to_sign.addAttribute("xmlns", "http://e-dokumenty.mf.gov.pl") catch {};
xml_to_sign.updateChildContent("DocumentType", "JPK");
xml_to_sign.updateChildContent("Version", "01.02.01.20160617");
xml_to_sign.updateAttrAt("EncryptionKey", true, "algorithm", "RSA") catch {};
xml_to_sign.updateAttrAt("EncryptionKey", true, "encoding", "Base64") catch {};
xml_to_sign.updateAttrAt("EncryptionKey", true, "mode", "ECB") catch {};
xml_to_sign.updateAttrAt("EncryptionKey", true, "padding", "PKCS#1") catch {};
xml_to_sign.updateChildContent("EncryptionKey", "xxxx");
xml_to_sign.updateAttrAt("DocumentList|Document|FormCode", true, "schemaVersion", "1-1") catch {};
xml_to_sign.updateAttrAt("DocumentList|Document|FormCode", true, "systemCode", "JPK_VAT (3)") catch {};
xml_to_sign.updateChildContent("DocumentList|Document|FormCode", "JPK_VAT");
xml_to_sign.updateChildContent("DocumentList|Document|FileName", "JPK_VAT_3_v1-1_20181201.xml");
xml_to_sign.updateChildContent("DocumentList|Document|ContentLength", "8736");
xml_to_sign.updateAttrAt("DocumentList|Document|HashValue", true, "algorithm", "SHA-256") catch {};
xml_to_sign.updateAttrAt("DocumentList|Document|HashValue", true, "encoding", "Base64") catch {};
xml_to_sign.updateChildContent("DocumentList|Document|HashValue", "JEDI1pItwh6dj/Xx1uts/x61qnjZ4DLHpkZMhmf1oKQ=");
xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList", true, "filesNumber", "1") catch {};
xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Packaging|SplitZip", true, "mode", "zip") catch {};
xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Packaging|SplitZip", true, "type", "split") catch {};
xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "block", "16") catch {};
xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "mode", "CBC") catch {};
xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "padding", "PKCS#7") catch {};
xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "size", "256") catch {};
xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES|IV", true, "bytes", "16") catch {};
xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES|IV", true, "encoding", "Base64") catch {};
xml_to_sign.updateChildContent("DocumentList|Document|FileSignatureList|Encryption|AES|IV", "z64oN9zXHt1+S3XACRSCYw==");
xml_to_sign.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|OrdinalNumber", "1");
xml_to_sign.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|FileName", "JPK_VAT_3_v1-1_20181201-000.xml.zip.aes");
xml_to_sign.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|ContentLength", "16");
xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|FileSignature|HashValue", true, "algorithm", "MD5") catch {};
xml_to_sign.updateAttrAt("DocumentList|Document|FileSignatureList|FileSignature|HashValue", true, "encoding", "Base64") catch {};
xml_to_sign.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|HashValue", "5MX0q1935fvMjLFV7E1yDw==");
const gen = try chilkat.XmlDSigGen.init();
defer gen.deinit();
gen.setSigLocation("InitUpload");
gen.setSigLocationMod(0);
gen.setSigId("id-1234");
gen.setSigNamespacePrefix("ds");
gen.setSigNamespaceUri("http://www.w3.org/2000/09/xmldsig#");
gen.setSignedInfoCanonAlg("EXCL_C14N");
gen.setSignedInfoDigestMethod("sha256");
// Create an Object to be added to the Signature.
// <xades:QualifyingProperties Target="#id-1234" xmlns:xades="http://uri.etsi.org/01903/v1.3.2#">
// <xades:SignedProperties Id="xades-id-1234">
// <xades:SignedSignatureProperties>
// <xades:SigningTime>TO BE GENERATED BY CHILKAT</xades:SigningTime>
// <xades:SigningCertificate>
// <xades:Cert>
// <xades:CertDigest>
// <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
// <ds:DigestValue>TO BE GENERATED BY CHILKAT</ds:DigestValue>
// </xades:CertDigest>
// <xades:IssuerSerial>
// <ds:X509IssuerName>TO BE GENERATED BY CHILKAT</ds:X509IssuerName>
// <ds:X509SerialNumber>TO BE GENERATED BY CHILKAT</ds:X509SerialNumber>
// </xades:IssuerSerial>
// </xades:Cert>
// </xades:SigningCertificate>
// </xades:SignedSignatureProperties>
// <xades:SignedDataObjectProperties>
// <xades:DataObjectFormat ObjectReference="#r-id-1">
// <xades:MimeType>text/xml</xades:MimeType>
// </xades:DataObjectFormat>
// </xades:SignedDataObjectProperties>
// </xades:SignedProperties>
// </xades:QualifyingProperties>
const object1 = try chilkat.Xml.init();
defer object1.deinit();
object1.setTag("xades:QualifyingProperties");
object1.addAttribute("xmlns:xades", "http://uri.etsi.org/01903/v1.3.2#") catch {};
object1.addAttribute("Target", "#id-1234") catch {};
object1.updateAttrAt("xades:SignedProperties", true, "Id", "xades-id-1234") catch {};
// Note: It may be that http://www.w3.org/2001/04/xmlenc#sha256 is needed in the following line instead of http://www.w3.org/2000/09/xmldsig#sha1
object1.updateChildContent("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningTime", "TO BE GENERATED BY CHILKAT");
object1.updateAttrAt("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningCertificateV2|xades:Cert|xades:CertDigest|ds:DigestMethod", true, "Algorithm", "http://www.w3.org/2000/09/xmldsig#sha1") catch {};
object1.updateChildContent("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningCertificateV2|xades:Cert|xades:CertDigest|ds:DigestValue", "TO BE GENERATED BY CHILKAT");
object1.updateChildContent("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningCertificateV2|xades:Cert|xades:IssuerSerialV2", "TO BE GENERATED BY CHILKAT");
object1.updateAttrAt("xades:SignedProperties|xades:SignedDataObjectProperties|xades:DataObjectFormat", true, "ObjectReference", "#r-id-1") catch {};
object1.updateChildContent("xades:SignedProperties|xades:SignedDataObjectProperties|xades:DataObjectFormat|xades:MimeType", "text/xml");
gen.addObject("", try object1.getXml(alloc), "", "") catch {};
// -------- Reference 1 --------
// Build the following Transforms fragment:
// <ds:Transforms>
// <ds:Transform Algorithm="http://www.w3.org/TR/1999/REC-xpath-19991116">
// <ds:XPath>not(ancestor-or-self::ds:Signature)</ds:XPath>
// </ds:Transform>
// <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
// </ds:Transforms>
const xml1 = try chilkat.Xml.init();
defer xml1.deinit();
xml1.setTag("ds:Transforms");
xml1.updateAttrAt("ds:Transform", true, "Algorithm", "http://www.w3.org/TR/1999/REC-xpath-19991116") catch {};
xml1.updateChildContent("ds:Transform|ds:XPath", "not(ancestor-or-self::ds:Signature)");
xml1.updateAttrAt("ds:Transform[1]", true, "Algorithm", "http://www.w3.org/2001/10/xml-exc-c14n#") catch {};
gen.addSameDocRef2("", "sha256", xml1, "") catch {};
gen.setRefIdAttr("", "r-id-1") catch {};
// -------- Reference 2 --------
// Build the following Transforms fragment:
// <ds:Transforms>
// <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
// </ds:Transforms>
const xml2 = try chilkat.Xml.init();
defer xml2.deinit();
xml2.setTag("ds:Transforms");
xml2.updateAttrAt("ds:Transform", true, "Algorithm", "http://www.w3.org/2001/10/xml-exc-c14n#") catch {};
gen.addObjectRef2("xades-id-1234", "sha256", xml2, "http://uri.etsi.org/01903#SignedProperties") catch {};
// Provide a certificate + private key. (PFX password is test123)
const cert = try chilkat.Cert.init();
defer cert.deinit();
cert.loadPfxFile("qa_data/pfx/cert_test123.pfx", "test123") catch {
std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
return;
};
gen.setX509Cert(cert, true) catch {};
gen.setKeyInfoType("X509Data");
gen.setX509Type("Certificate");
// Load XML to be signed...
const sb_xml = try chilkat.StringBuilder.init();
defer sb_xml.deinit();
xml_to_sign.getXmlSb(sb_xml) catch {};
gen.setBehaviors("IndentedSignature");
// Sign the XML...
gen.createXmlDSigSb(sb_xml) catch {
std.debug.print("{s}\n", .{try gen.getLastErrorText(alloc)});
return;
};
// -----------------------------------------------
// Save the signed XML to a file.
try sb_xml.writeFile("qa_output/signedXml.xml", "utf-8", false);
std.debug.print("{s}\n", .{try sb_xml.getAsString(alloc)});
// ----------------------------------------
// Verify the signatures we just produced...
const verifier = try chilkat.XmlDSig.init();
defer verifier.deinit();
verifier.loadSignatureSb(sb_xml) catch {
std.debug.print("{s}\n", .{try verifier.getLastErrorText(alloc)});
return;
};
const num_sigs = verifier.getNumSignatures();
var verify_idx: i32 = 0;
while (verify_idx < num_sigs) {
verifier.setSelector(verify_idx);
verifier.verifySignature(true) catch {
std.debug.print("{s}\n", .{try verifier.getLastErrorText(alloc)});
return;
};
verify_idx = verify_idx + 1;
}
std.debug.print("All signatures were successfully verified.\n", .{});
}