Sample code for 30+ languages & platforms
Delphi DLL

SOAP WS-Security UsernameToken

See more XML Examples

Demonstrates how to add a UsernameToken with the WSS SOAP Message Security header.

Note: This example requires Chilkat v9.5.0.66 or later.

Chilkat Delphi DLL Downloads

Delphi DLL
uses
    Winapi.Windows, Winapi.Messages, System.SysUtils, System.Variants, System.Classes, Vcl.Graphics,
    Vcl.Controls, Vcl.Forms, Vcl.Dialogs, Vcl.StdCtrls, BinData, Prng, Xml, CkDateTime, Crypt2;

...

procedure TForm1.Button1Click(Sender: TObject);
var
xml: HCkXml;
wsse: HCkXml;
xHeader: HCkXml;
wsu_id: PWideChar;
password: PWideChar;
username: PWideChar;
prng: HCkPrng;
bd: HCkBinData;
nonce: PWideChar;
dt: HCkDateTime;
bLocal: Boolean;
created: PWideChar;
crypt: HCkCrypt2;
passwordDigest: PWideChar;

begin
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

// An HTTP SOAP request is an HTTP request where the SOAP XML composes the body.
// This example demonstrates how to add a WS-Security header such as the following:
// 
// <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="SecurityToken-6138db82-5a4c-4bf7-915f-af7a10d9ae96">
//   <wsse:Username>user</wsse:Username>
//   <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">CBb7a2itQDgxVkqYnFtggUxtuqk=</wsse:Password>
//   <wsse:Nonce>5ABcqPZWb6ImI2E6tob8MQ==</wsse:Nonce>
//   <wsu:Created>2010-06-08T07:26:50Z</wsu:Created>
// </wsse:UsernameToken>
// 

// First build some simple SOAP XML that has some header and body.
xml := CkXml_Create();
CkXml_putTag(xml,'env:Envelope');
CkXml_AddAttribute(xml,'xmlns:env','http://www.w3.org/2003/05/soap-envelope');
CkXml_UpdateAttrAt(xml,'env:Header|n:alertcontrol',True,'xmlns:n','http://example.org/alertcontrol');
CkXml_UpdateChildContent(xml,'env:Header|n:alertcontrol|n:priority','1');
CkXml_UpdateChildContent(xml,'env:Header|n:alertcontrol|n:expires','2001-06-22T14:00:00-05:00');
CkXml_UpdateAttrAt(xml,'env:Body|m:alert',True,'xmlns:m','http://example.org/alert');
CkXml_UpdateChildContent(xml,'env:Body|m:alert|m:msg','Pick up Mary at school at 2pm');
Memo1.Lines.Add(CkXml__getXml(xml));
Memo1.Lines.Add('----');

// The following SOAP XML is built:

// 	<env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope">
// 	 <env:Header>
// 	  <n:alertcontrol xmlns:n="http://example.org/alertcontrol">
// 	   <n:priority>1</n:priority>
// 	   <n:expires>2001-06-22T14:00:00-05:00</n:expires>
// 	  </n:alertcontrol>
// 	 </env:Header>
// 	 <env:Body>
// 	  <m:alert xmlns:m="http://example.org/alert">
// 	   <m:msg>Pick up Mary at school at 2pm</m:msg>
// 	  </m:alert>
// 	 </env:Body>
// 	</env:Envelope>
// 

// Now build the WSSE XML housing that we'll insert into the above SOAP XML at the end.

// 	<wsse:Security>
// 	  <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="WSU_ID">
// 	    <wsse:Username>USERNAME</wsse:Username>
// 	    <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">PASSWORD_DIGEST</wsse:Password>
// 	    <wsse:Nonce>NONCE</wsse:Nonce>
// 	    <wsu:Created>CREATED</wsu:Created>
// 	  </wsse:UsernameToken>
// 	</wsse:Security>

wsse := CkXml_Create();
CkXml_putTag(wsse,'wsse:Security');
CkXml_UpdateAttrAt(wsse,'wsse:UsernameToken',True,'xmlns:wsu','http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd');
CkXml_UpdateAttrAt(wsse,'wsse:UsernameToken',True,'wsu:Id','WSU_ID');
CkXml_UpdateChildContent(wsse,'wsse:UsernameToken|wsse:Username','USERNAME');
CkXml_UpdateAttrAt(wsse,'wsse:UsernameToken|wsse:Password',True,'Type','http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest');
CkXml_UpdateChildContent(wsse,'wsse:UsernameToken|wsse:Password','PASSWORD_DIGEST');
CkXml_UpdateChildContent(wsse,'wsse:UsernameToken|wsse:Nonce','NONCE');
CkXml_UpdateChildContent(wsse,'wsse:UsernameToken|wsu:Created','CREATED');
Memo1.Lines.Add(CkXml__getXml(wsse));
Memo1.Lines.Add('----');

// Insert the wsse:Security XML into the existing SOAP header:
xHeader := CkXml_GetChildWithTag(xml,'env:Header');
CkXml_AddChildTree(xHeader,wsse);
CkXml_Dispose(xHeader);

// Now show the SOAP XML with the wsse:Security header added:
Memo1.Lines.Add(CkXml__getXml(xml));
Memo1.Lines.Add('----');

// Now our XML looks like this:
// 	<env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope">
// 	    <env:Header>
// 	        <n:alertcontrol xmlns:n="http://example.org/alertcontrol">
// 	            <n:priority>1</n:priority>
// 	            <n:expires>2001-06-22T14:00:00-05:00</n:expires>
// 	        </n:alertcontrol>
// 	        <wsse:Security>
// 	            <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="WSU_ID">
// 	                <wsse:Username>USERNAME</wsse:Username>
// 	                <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">PASSWORD_DIGEST</wsse:Password>
// 	                <wsse:Nonce>NONCE</wsse:Nonce>
// 	                <wsu:Created>CREATED</wsu:Created>
// 	            </wsse:UsernameToken>
// 	        </wsse:Security>
// 	    </env:Header>
// 	    <env:Body>
// 	        <m:alert xmlns:m="http://example.org/alert">
// 	            <m:msg>Pick up Mary at school at 2pm</m:msg>
// 	        </m:alert>
// 	    </env:Body>
// 	</env:Envelope>
// 

// -----------------------------------------------------
// Now let's fill-in-the-blanks with actual information...
// -----------------------------------------------------

wsu_id := 'Example-1';
CkXml_UpdateAttrAt(wsse,'wsse:UsernameToken',True,'wsu:Id',wsu_id);

password := 'password';
username := 'user';
CkXml_UpdateChildContent(wsse,'wsse:UsernameToken|wsse:Username',username);

// The nonce should be 16 random bytes.
prng := CkPrng_Create();
bd := CkBinData_Create();
// Generate 16 random bytes into bd.
// Note: The GenRandomBd method is added in Chilkat v9.5.0.66
CkPrng_GenRandomBd(prng,16,bd);

nonce := CkBinData__getEncoded(bd,'base64');
CkXml_UpdateChildContent(wsse,'wsse:UsernameToken|wsse:Nonce',nonce);

// Get the current date/time in a string with this format: 2010-06-08T07:26:50Z
dt := CkDateTime_Create();
CkDateTime_SetFromCurrentSystemTime(dt);
bLocal := False;
created := CkDateTime__getAsTimestamp(dt,bLocal);
CkXml_UpdateChildContent(wsse,'wsse:UsernameToken|wsu:Created',created);

// The password digest is calculated like this:
// Password_Digest = Base64 ( SHA-1 ( nonce + created + password ) )
CkBinData_AppendString(bd,created,'utf-8');
CkBinData_AppendString(bd,password,'utf-8');

crypt := CkCrypt2_Create();
CkCrypt2_putHashAlgorithm(crypt,'SHA-1');
CkCrypt2_putEncodingMode(crypt,'base64');
// Note: The HashBdENC method is added in Chilkat v9.5.0.66
passwordDigest := CkCrypt2__hashBdENC(crypt,bd);
CkXml_UpdateChildContent(wsse,'wsse:UsernameToken|wsse:Password',passwordDigest);

// Examine the final SOAP XML with WS-Security header added.
Memo1.Lines.Add(CkXml__getXml(xml));

CkXml_Dispose(xml);
CkXml_Dispose(wsse);
CkPrng_Dispose(prng);
CkBinData_Dispose(bd);
CkDateTime_Dispose(dt);
CkCrypt2_Dispose(crypt);

end;