Sample code for 30+ languages & platforms
Zig

XML-DSig Add Reference with Transforms Specified Explicitly

Demonstrates how to use the new AddSameDocRef2 method to explicitly specify the XML Transforms fragment.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // Create the following XML to be signed:

    // <doc>
    //     <s id="s1">Some text...</s>
    //     <p>Some text...</p>
    //     <p class="note">A note...</p>
    // </doc>

    // Use this online tool to generate code from sample XML:
    // Generate Code to Create XML

    const xml_to_sign = try chilkat.Xml.init();
    defer xml_to_sign.deinit();
    xml_to_sign.setTag("doc");
    xml_to_sign.updateAttrAt("s", true, "id", "s1") catch {};
    xml_to_sign.updateChildContent("s", "Some text...");
    xml_to_sign.updateChildContent("p", "Some text...");
    xml_to_sign.updateAttrAt("p[1]", true, "class", "note") catch {};
    xml_to_sign.updateChildContent("p[1]", "A note...");

    std.debug.print("{s}\n", .{try xml_to_sign.getXml(alloc)});

    const gen = try chilkat.XmlDSigGen.init();
    defer gen.deinit();

    gen.setSigLocation("doc");
    gen.setSigLocationMod(0);
    gen.setSigId("Signature-78f29839-06af-448f-b479-ca46457fab1b-Signature");
    gen.setSigNamespacePrefix("ds");
    gen.setSigNamespaceUri("http://www.w3.org/2000/09/xmldsig#");
    gen.setSigValueId("Signature-78f29839-06af-448f-b479-ca46457fab1b-SignatureValue");
    gen.setSignedInfoCanonAlg("C14N");
    gen.setSignedInfoDigestMethod("sha1");

    // Set the KeyInfoId before adding references..
    gen.setKeyInfoId("Signature-78f29839-06af-448f-b479-ca46457fab1b-KeyInfo");

    // The following XML to be added as an Object to the Signature

    // Use this online tool to generate code from sample XML:
    // Generate Code to Create XML

    // <xades:QualifyingProperties Id="Signature-78f29839-06af-448f-b479-ca46457fab1b-QualifyingProperties" Target="#Signature-78f29839-06af-448f-b479-ca46457fab1b-Signature" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:xades="http://uri.etsi.org/01903/v1.3.2#">
    //     <xades:SignedProperties Id="Signature-78f29839-06af-448f-b479-ca46457fab1b-SignedProperties">
    //         <xades:SignedSignatureProperties>
    //             <xades:SigningTime>TO BE GENERATED BY CHILKAT</xades:SigningTime>
    //             <xades:SigningCertificate>
    //                 <xades:Cert>
    //                     <xades:CertDigest>
    //                         <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
    //                         <ds:DigestValue>TO BE GENERATED BY CHILKAT</ds:DigestValue>
    //                     </xades:CertDigest>
    //                     <xades:IssuerSerial>
    //                         <ds:X509IssuerName>TO BE GENERATED BY CHILKAT</ds:X509IssuerName>
    //                         <ds:X509SerialNumber>TO BE GENERATED BY CHILKAT</ds:X509SerialNumber>
    //                     </xades:IssuerSerial>
    //                 </xades:Cert>
    //             </xades:SigningCertificate>
    //         </xades:SignedSignatureProperties>
    //         <xades:SignedDataObjectProperties>
    //             <xades:DataObjectFormat ObjectReference="#Reference-24eb6003-d41c-442c-a731-d4c58f94790b">
    //                 <xades:Description/>
    //                 <xades:ObjectIdentifier>
    //                     <xades:Identifier Qualifier="OIDAsURN">urn:oid:1.2.840.10003.5.109.10</xades:Identifier>
    //                     <xades:Description/>
    //                 </xades:ObjectIdentifier>
    //                 <xades:MimeType>text/xml</xades:MimeType>
    //                 <xades:Encoding/>
    //             </xades:DataObjectFormat>
    //         </xades:SignedDataObjectProperties>
    //     </xades:SignedProperties>
    // </xades:QualifyingProperties>

    const object1 = try chilkat.Xml.init();
    defer object1.deinit();
    object1.setTag("xades:QualifyingProperties");
    object1.addAttribute("Id", "Signature-78f29839-06af-448f-b479-ca46457fab1b-QualifyingProperties") catch {};
    object1.addAttribute("Target", "#Signature-78f29839-06af-448f-b479-ca46457fab1b-Signature") catch {};
    object1.addAttribute("xmlns:ds", "http://www.w3.org/2000/09/xmldsig#") catch {};
    object1.addAttribute("xmlns:xades", "http://uri.etsi.org/01903/v1.3.2#") catch {};
    object1.updateAttrAt("xades:SignedProperties", true, "Id", "Signature-78f29839-06af-448f-b479-ca46457fab1b-SignedProperties") catch {};
    object1.updateChildContent("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningTime", "TO BE GENERATED BY CHILKAT");
    // Note: It may be that http://www.w3.org/2001/04/xmlenc#sha256 is needed in the following line instead of http://www.w3.org/2000/09/xmldsig#sha1
    object1.updateAttrAt("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningCertificateV2|xades:Cert|xades:CertDigest|ds:DigestMethod", true, "Algorithm", "http://www.w3.org/2000/09/xmldsig#sha1") catch {};
    object1.updateChildContent("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningCertificateV2|xades:Cert|xades:CertDigest|ds:DigestValue", "TO BE GENERATED BY CHILKAT");
    object1.updateChildContent("xades:SignedProperties|xades:SignedSignatureProperties|xades:SigningCertificateV2|xades:Cert|xades:IssuerSerialV2", "TO BE GENERATED BY CHILKAT");
    object1.updateAttrAt("xades:SignedProperties|xades:SignedDataObjectProperties|xades:DataObjectFormat", true, "ObjectReference", "#Reference-24eb6003-d41c-442c-a731-d4c58f94790b") catch {};
    object1.updateChildContent("xades:SignedProperties|xades:SignedDataObjectProperties|xades:DataObjectFormat|xades:Description", "");
    object1.updateAttrAt("xades:SignedProperties|xades:SignedDataObjectProperties|xades:DataObjectFormat|xades:ObjectIdentifier|xades:Identifier", true, "Qualifier", "OIDAsURN") catch {};
    object1.updateChildContent("xades:SignedProperties|xades:SignedDataObjectProperties|xades:DataObjectFormat|xades:ObjectIdentifier|xades:Identifier", "urn:oid:1.2.840.10003.5.109.10");
    object1.updateChildContent("xades:SignedProperties|xades:SignedDataObjectProperties|xades:DataObjectFormat|xades:ObjectIdentifier|xades:Description", "");
    object1.updateChildContent("xades:SignedProperties|xades:SignedDataObjectProperties|xades:DataObjectFormat|xades:MimeType", "text/xml");
    object1.updateChildContent("xades:SignedProperties|xades:SignedDataObjectProperties|xades:DataObjectFormat|xades:Encoding", "");

    std.debug.print("{s}\n", .{try object1.getXml(alloc)});

    gen.addObject("", try object1.getXml(alloc), "", "") catch {};

    // -------- Reference 1 --------

    // Create the following Transforms fragment:

    // Use this online tool to generate code from sample XML:
    // Generate Code to Create XML

    // <ds:Transforms>
    //     <ds:Transform Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-20010315"/>
    //     <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
    //     <ds:Transform Algorithm="http://www.w3.org/TR/1999/REC-xpath-19991116">
    //         <ds:XPath xmlns:ds="http://www.w3.org/2000/09/xmldsig#">not(ancestor-or-self::ds:Signature)</ds:XPath>
    //     </ds:Transform>
    // </ds:Transforms>

    const xml1 = try chilkat.Xml.init();
    defer xml1.deinit();
    xml1.setTag("ds:Transforms");
    xml1.updateAttrAt("ds:Transform", true, "Algorithm", "http://www.w3.org/TR/2001/REC-xml-c14n-20010315") catch {};
    xml1.updateAttrAt("ds:Transform[1]", true, "Algorithm", "http://www.w3.org/2000/09/xmldsig#enveloped-signature") catch {};
    xml1.updateAttrAt("ds:Transform[2]", true, "Algorithm", "http://www.w3.org/TR/1999/REC-xpath-19991116") catch {};
    xml1.updateAttrAt("ds:Transform[2]|ds:XPath", true, "xmlns:ds", "http://www.w3.org/2000/09/xmldsig#") catch {};
    xml1.updateChildContent("ds:Transform[2]|ds:XPath", "not(ancestor-or-self::ds:Signature)");

    // This is the "Transforms" XML fragment passed to AddSameDocRef2.
    std.debug.print("{s}\n", .{try xml1.getXml(alloc)});

    gen.addSameDocRef2("", "sha1", xml1, "") catch {};

    gen.setRefIdAttr("", "Reference-24eb6003-d41c-442c-a731-d4c58f94790b") catch {};

    // -------- Reference 2 --------
    gen.addObjectRef("Signature-78f29839-06af-448f-b479-ca46457fab1b-SignedProperties", "sha1", "", "", "http://uri.etsi.org/01903#SignedProperties") catch {};

    // -------- Reference 3 --------
    gen.addSameDocRef("Signature-78f29839-06af-448f-b479-ca46457fab1b-KeyInfo", "sha1", "", "", "") catch {};

    // Provide a certificate + private key. (PFX password is test123)
    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    cert.loadPfxFile("qa_data/pfx/cert_test123.pfx", "test123") catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    gen.setX509Cert(cert, true) catch {};

    gen.setKeyInfoType("X509Data+KeyValue");
    gen.setX509Type("CertChain");

    // Load XML to be signed...
    const sb_xml = try chilkat.StringBuilder.init();
    defer sb_xml.deinit();
    xml_to_sign.getXmlSb(sb_xml) catch {};

    gen.setBehaviors("IndentedSignature");

    // Sign the XML...
    gen.createXmlDSigSb(sb_xml) catch {
        std.debug.print("{s}\n", .{try gen.getLastErrorText(alloc)});
        return;
    };

    // -----------------------------------------------

    // Save the signed XML to a file.
    try sb_xml.writeFile("qa_output/signedXml.xml", "utf-8", false);

    std.debug.print("{s}\n", .{try sb_xml.getAsString(alloc)});

    // ----------------------------------------
    // Verify the signatures we just produced...
    const verifier = try chilkat.XmlDSig.init();
    defer verifier.deinit();
    verifier.loadSignatureSb(sb_xml) catch {
        std.debug.print("{s}\n", .{try verifier.getLastErrorText(alloc)});
        return;
    };

    const num_sigs = verifier.getNumSignatures();
    var verify_idx: i32 = 0;
    while (verify_idx < num_sigs) {
        verifier.setSelector(verify_idx);
        verifier.verifySignature(true) catch {
            std.debug.print("{s}\n", .{try verifier.getLastErrorText(alloc)});
            return;
        };

        verify_idx = verify_idx + 1;
    }

    std.debug.print("All signatures were successfully verified.\n", .{});
}