Sample code for 30+ languages & platforms
Delphi ActiveX

HMRC Validate Fraud Prevention Headers

See more HTTP Misc Examples

Demonstrates how to test (validate) HMRC fraud prevention headers.

Chilkat Delphi ActiveX Downloads

Delphi ActiveX
uses
    Winapi.Windows, Winapi.Messages, System.SysUtils, System.Variants, System.Classes, Vcl.Graphics,
    Vcl.Controls, Vcl.Forms, Vcl.Dialogs, Vcl.StdCtrls, Chilkat_TLB;

...

procedure TForm1.Button1Click(Sender: TObject);
var
success: Integer;
rest: TChilkatRest;
json: TChilkatJsonObject;
accessToken: WideString;
sbAuthHeaderValue: TChilkatStringBuilder;
responseStr: WideString;

begin
success := 0;

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

rest := TChilkatRest.Create(Self);

success := rest.Connect('test-api.service.hmrc.gov.uk',443,1,1);
if (success = 0) then
  begin
    Memo1.Lines.Add(rest.LastErrorText);
    Exit;
  end;

// Load the previously fetched access token.
json := TChilkatJsonObject.Create(Self);
success := json.LoadFile('qa_data/tokens/hmrc.json');
accessToken := json.StringOf('access_token');
Memo1.Lines.Add('Using access toke: ' + accessToken);

sbAuthHeaderValue := TChilkatStringBuilder.Create(Self);
sbAuthHeaderValue.Append('Bearer ');
sbAuthHeaderValue.Append(accessToken);

rest.AddHeader('Accept','application/vnd.hmrc.1.0+json');
rest.AddHeader('Authorization',sbAuthHeaderValue.GetAsString());

// Add the fraud prevention headers.
// See https://developer.service.hmrc.gov.uk/api-documentation/docs/fraud-prevention
rest.AddHeader('gov-client-connection-method','DESKTOP_APP_DIRECT');

// This should be generated by an application and persistently stored on the device. The identifier should not expire.
rest.AddHeader('gov-client-device-id','beec798b-b366-47fa-b1f8-92cede14a1ce');

// See https://developer.service.hmrc.gov.uk/api-documentation/docs/fraud-prevention
rest.AddHeader('gov-client-user-ids','os=user123');

// Your local IP addresses (comma separated), such as addresses beginning with "192.168." or "172.16."
rest.AddHeader('gov-client-local-ips','172.16.16.23');
// You'll need to find a way to get your MAC address.  Chilkat does not yet provide this ability...
rest.AddHeader('gov-client-mac-addresses','7C%3AD3%3A0A%3A25%3ADA%3A1C');

rest.AddHeader('gov-client-timezone','UTC+00:00');

// You can probably just hard-code these so they're always the same with each request.
rest.AddHeader('gov-client-window-size','width=1256&height=800');
rest.AddHeader('gov-client-screens','width=1920&height=1080&scaling-factor=1&colour-depth=16');
rest.AddHeader('gov-client-user-agent','Windows/Server%202012 (Dell%20Inc./OptiPlex%20980)');
rest.AddHeader('gov-vendor-version','My%20Desktop%20Software=1.2.3.build4286');

responseStr := rest.FullRequestNoBody('GET','/test/fraud-prevention-headers/validate');
if (rest.LastMethodSuccess = 0) then
  begin
    Memo1.Lines.Add(rest.LastErrorText);
    Exit;
  end;

// If the status code is 200, then the fraud prevention headers were validated.
// The JSON response may include some warnings..
Memo1.Lines.Add('Response status code = ' + IntToStr(rest.ResponseStatusCode));
Memo1.Lines.Add('Response JSON body: ');
Memo1.Lines.Add(responseStr);
end;