Sample code for 30+ languages & platforms
Dart

SOAP WS-Security UsernameToken

See more XML Examples

Demonstrates how to add a UsernameToken with the WSS SOAP Message Security header.

Note: This example requires Chilkat v9.5.0.66 or later.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This example requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  // An HTTP SOAP request is an HTTP request where the SOAP XML composes the body.
  // This example demonstrates how to add a WS-Security header such as the following:
  // 
  // <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="SecurityToken-6138db82-5a4c-4bf7-915f-af7a10d9ae96">
  //   <wsse:Username>user</wsse:Username>
  //   <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">CBb7a2itQDgxVkqYnFtggUxtuqk=</wsse:Password>
  //   <wsse:Nonce>5ABcqPZWb6ImI2E6tob8MQ==</wsse:Nonce>
  //   <wsu:Created>2010-06-08T07:26:50Z</wsu:Created>
  // </wsse:UsernameToken>
  // 

  // First build some simple SOAP XML that has some header and body.
  final xml = CkXml();
  xml.tag = 'env:Envelope';
  xml.addAttribute('xmlns:env', 'http://www.w3.org/2003/05/soap-envelope');
  xml.updateAttrAt('env:Header|n:alertcontrol', true, 'xmlns:n', 'http://example.org/alertcontrol');
  xml.updateChildContent('env:Header|n:alertcontrol|n:priority', '1');
  xml.updateChildContent('env:Header|n:alertcontrol|n:expires', '2001-06-22T14:00:00-05:00');
  xml.updateAttrAt('env:Body|m:alert', true, 'xmlns:m', 'http://example.org/alert');
  xml.updateChildContent('env:Body|m:alert|m:msg', 'Pick up Mary at school at 2pm');
  print(xml.getXml());
  print('----');

  // The following SOAP XML is built:

  // 	<env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope">
  // 	 <env:Header>
  // 	  <n:alertcontrol xmlns:n="http://example.org/alertcontrol">
  // 	   <n:priority>1</n:priority>
  // 	   <n:expires>2001-06-22T14:00:00-05:00</n:expires>
  // 	  </n:alertcontrol>
  // 	 </env:Header>
  // 	 <env:Body>
  // 	  <m:alert xmlns:m="http://example.org/alert">
  // 	   <m:msg>Pick up Mary at school at 2pm</m:msg>
  // 	  </m:alert>
  // 	 </env:Body>
  // 	</env:Envelope>
  // 

  // Now build the WSSE XML housing that we'll insert into the above SOAP XML at the end.

  // 	<wsse:Security>
  // 	  <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="WSU_ID">
  // 	    <wsse:Username>USERNAME</wsse:Username>
  // 	    <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">PASSWORD_DIGEST</wsse:Password>
  // 	    <wsse:Nonce>NONCE</wsse:Nonce>
  // 	    <wsu:Created>CREATED</wsu:Created>
  // 	  </wsse:UsernameToken>
  // 	</wsse:Security>

  final wsse = CkXml();
  wsse.tag = 'wsse:Security';
  wsse.updateAttrAt('wsse:UsernameToken', true, 'xmlns:wsu', 'http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd');
  wsse.updateAttrAt('wsse:UsernameToken', true, 'wsu:Id', 'WSU_ID');
  wsse.updateChildContent('wsse:UsernameToken|wsse:Username', 'USERNAME');
  wsse.updateAttrAt('wsse:UsernameToken|wsse:Password', true, 'Type', 'http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest');
  wsse.updateChildContent('wsse:UsernameToken|wsse:Password', 'PASSWORD_DIGEST');
  wsse.updateChildContent('wsse:UsernameToken|wsse:Nonce', 'NONCE');
  wsse.updateChildContent('wsse:UsernameToken|wsu:Created', 'CREATED');
  print(wsse.getXml());
  print('----');

  // Insert the wsse:Security XML into the existing SOAP header:
  final xHeader = xml.getChildWithTag('env:Header');
  xHeader.addChildTree(wsse);

  // Now show the SOAP XML with the wsse:Security header added:
  print(xml.getXml());
  print('----');

  // Now our XML looks like this:
  // 	<env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope">
  // 	    <env:Header>
  // 	        <n:alertcontrol xmlns:n="http://example.org/alertcontrol">
  // 	            <n:priority>1</n:priority>
  // 	            <n:expires>2001-06-22T14:00:00-05:00</n:expires>
  // 	        </n:alertcontrol>
  // 	        <wsse:Security>
  // 	            <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="WSU_ID">
  // 	                <wsse:Username>USERNAME</wsse:Username>
  // 	                <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">PASSWORD_DIGEST</wsse:Password>
  // 	                <wsse:Nonce>NONCE</wsse:Nonce>
  // 	                <wsu:Created>CREATED</wsu:Created>
  // 	            </wsse:UsernameToken>
  // 	        </wsse:Security>
  // 	    </env:Header>
  // 	    <env:Body>
  // 	        <m:alert xmlns:m="http://example.org/alert">
  // 	            <m:msg>Pick up Mary at school at 2pm</m:msg>
  // 	        </m:alert>
  // 	    </env:Body>
  // 	</env:Envelope>
  // 

  // -----------------------------------------------------
  // Now let's fill-in-the-blanks with actual information...
  // -----------------------------------------------------

  final wsuId = 'Example-1';
  wsse.updateAttrAt('wsse:UsernameToken', true, 'wsu:Id', wsuId);

  final password = 'password';
  final username = 'user';
  wsse.updateChildContent('wsse:UsernameToken|wsse:Username', username);

  // The nonce should be 16 random bytes.
  final prng = CkPrng();
  final bd = CkBinData();
  // Generate 16 random bytes into bd.
  // Note: The GenRandomBd method is added in Chilkat v9.5.0.66
  prng.genRandomBd(16, bd);

  final nonce = bd.getEncoded('base64');
  wsse.updateChildContent('wsse:UsernameToken|wsse:Nonce', nonce);

  // Get the current date/time in a string with this format: 2010-06-08T07:26:50Z
  final dt = CkDateTime();
  dt.setFromCurrentSystemTime();
  final bLocal = false;
  final created = dt.getAsTimestamp(bLocal);
  wsse.updateChildContent('wsse:UsernameToken|wsu:Created', created);

  // The password digest is calculated like this:
  // Password_Digest = Base64 ( SHA-1 ( nonce + created + password ) )
  bd.appendString(created, 'utf-8');
  bd.appendString(password, 'utf-8');

  final crypt = CkCrypt2();
  crypt.hashAlgorithm = 'SHA-1';
  crypt.encodingMode = 'base64';
  // Note: The HashBdENC method is added in Chilkat v9.5.0.66
  final passwordDigest = crypt.hashBdENC(bd);
  wsse.updateChildContent('wsse:UsernameToken|wsse:Password', passwordDigest);

  // Examine the final SOAP XML with WS-Security header added.
  print(xml.getXml());
}