Chilkat HOME Android™ AutoIt C C# C++ Chilkat2-Python CkPython Classic ASP DataFlex Delphi DLL Go Java Node.js Objective-C PHP Extension Perl PowerBuilder PowerShell PureBasic Ruby SQL Server Swift Tcl Unicode C Unicode C++ VB.NET VBScript Visual Basic 6.0 Visual FoxPro Xojo Plugin
(Visual FoxPro) SOAP WS-Security UsernameTokenDemonstrates how to add a UsernameToken with the WSS SOAP Message Security header. Note: This example requires Chilkat v9.5.0.66 or later.
LOCAL loXml LOCAL loWsse LOCAL loXHeader LOCAL lcWsu_id LOCAL lcPassword LOCAL lcUsername LOCAL loPrng LOCAL loBd LOCAL lcNonce LOCAL loDt LOCAL lnBLocal LOCAL lcCreated LOCAL loCrypt LOCAL lcPasswordDigest * This example requires the Chilkat Crypt API to have been previously unlocked. * See Unlock Chilkat Crypt for sample code. * An HTTP SOAP request is an HTTP request where the SOAP XML composes the body. * This example demonstrates how to add a WS-Security header such as the following: * * <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="SecurityToken-6138db82-5a4c-4bf7-915f-af7a10d9ae96"> * <wsse:Username>user</wsse:Username> * <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">CBb7a2itQDgxVkqYnFtggUxtuqk=</wsse:Password> * <wsse:Nonce>5ABcqPZWb6ImI2E6tob8MQ==</wsse:Nonce> * <wsu:Created>2010-06-08T07:26:50Z</wsu:Created> * </wsse:UsernameToken> * * First build some simple SOAP XML that has some header and body. * For versions of Chilkat < 10.0.0, use CreateObject('Chilkat_9_5_0.Xml') loXml = CreateObject('Chilkat.Xml') loXml.Tag = "env:Envelope" loXml.AddAttribute("xmlns:env","http://www.w3.org/2003/05/soap-envelope") loXml.UpdateAttrAt("env:Header|n:alertcontrol",1,"xmlns:n","http://example.org/alertcontrol") loXml.UpdateChildContent("env:Header|n:alertcontrol|n:priority","1") loXml.UpdateChildContent("env:Header|n:alertcontrol|n:expires","2001-06-22T14:00:00-05:00") loXml.UpdateAttrAt("env:Body|m:alert",1,"xmlns:m","http://example.org/alert") loXml.UpdateChildContent("env:Body|m:alert|m:msg","Pick up Mary at school at 2pm") ? loXml.GetXml() ? "----" * The following SOAP XML is built: * <env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope"> * <env:Header> * <n:alertcontrol xmlns:n="http://example.org/alertcontrol"> * <n:priority>1</n:priority> * <n:expires>2001-06-22T14:00:00-05:00</n:expires> * </n:alertcontrol> * </env:Header> * <env:Body> * <m:alert xmlns:m="http://example.org/alert"> * <m:msg>Pick up Mary at school at 2pm</m:msg> * </m:alert> * </env:Body> * </env:Envelope> * * Now build the WSSE XML housing that we'll insert into the above SOAP XML at the end. * <wsse:Security> * <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="WSU_ID"> * <wsse:Username>USERNAME</wsse:Username> * <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">PASSWORD_DIGEST</wsse:Password> * <wsse:Nonce>NONCE</wsse:Nonce> * <wsu:Created>CREATED</wsu:Created> * </wsse:UsernameToken> * </wsse:Security> * For versions of Chilkat < 10.0.0, use CreateObject('Chilkat_9_5_0.Xml') loWsse = CreateObject('Chilkat.Xml') loWsse.Tag = "wsse:Security" loWsse.UpdateAttrAt("wsse:UsernameToken",1,"xmlns:wsu","http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd") loWsse.UpdateAttrAt("wsse:UsernameToken",1,"wsu:Id","WSU_ID") loWsse.UpdateChildContent("wsse:UsernameToken|wsse:Username","USERNAME") loWsse.UpdateAttrAt("wsse:UsernameToken|wsse:Password",1,"Type","http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest") loWsse.UpdateChildContent("wsse:UsernameToken|wsse:Password","PASSWORD_DIGEST") loWsse.UpdateChildContent("wsse:UsernameToken|wsse:Nonce","NONCE") loWsse.UpdateChildContent("wsse:UsernameToken|wsu:Created","CREATED") ? loWsse.GetXml() ? "----" * Insert the wsse:Security XML into the existing SOAP header: loXHeader = loXml.GetChildWithTag("env:Header") loXHeader.AddChildTree(loWsse) RELEASE loXHeader * Now show the SOAP XML with the wsse:Security header added: ? loXml.GetXml() ? "----" * Now our XML looks like this: * <env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope"> * <env:Header> * <n:alertcontrol xmlns:n="http://example.org/alertcontrol"> * <n:priority>1</n:priority> * <n:expires>2001-06-22T14:00:00-05:00</n:expires> * </n:alertcontrol> * <wsse:Security> * <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="WSU_ID"> * <wsse:Username>USERNAME</wsse:Username> * <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">PASSWORD_DIGEST</wsse:Password> * <wsse:Nonce>NONCE</wsse:Nonce> * <wsu:Created>CREATED</wsu:Created> * </wsse:UsernameToken> * </wsse:Security> * </env:Header> * <env:Body> * <m:alert xmlns:m="http://example.org/alert"> * <m:msg>Pick up Mary at school at 2pm</m:msg> * </m:alert> * </env:Body> * </env:Envelope> * * ----------------------------------------------------- * Now let's fill-in-the-blanks with actual information... * ----------------------------------------------------- lcWsu_id = "Example-1" loWsse.UpdateAttrAt("wsse:UsernameToken",1,"wsu:Id",lcWsu_id) lcPassword = "password" lcUsername = "user" loWsse.UpdateChildContent("wsse:UsernameToken|wsse:Username",lcUsername) * The nonce should be 16 random bytes. * For versions of Chilkat < 10.0.0, use CreateObject('Chilkat_9_5_0.Prng') loPrng = CreateObject('Chilkat.Prng') * For versions of Chilkat < 10.0.0, use CreateObject('Chilkat_9_5_0.BinData') loBd = CreateObject('Chilkat.BinData') * Generate 16 random bytes into bd. * Note: The GenRandomBd method is added in Chilkat v9.5.0.66 loPrng.GenRandomBd(16,loBd) lcNonce = loBd.GetEncoded("base64") loWsse.UpdateChildContent("wsse:UsernameToken|wsse:Nonce",lcNonce) * Get the current date/time in a string with this format: 2010-06-08T07:26:50Z * For versions of Chilkat < 10.0.0, use CreateObject('Chilkat_9_5_0.CkDateTime') loDt = CreateObject('Chilkat.CkDateTime') loDt.SetFromCurrentSystemTime() lnBLocal = 0 lcCreated = loDt.GetAsTimestamp(lnBLocal) loWsse.UpdateChildContent("wsse:UsernameToken|wsu:Created",lcCreated) * The password digest is calculated like this: * Password_Digest = Base64 ( SHA-1 ( nonce + created + password ) ) loBd.AppendString(lcCreated,"utf-8") loBd.AppendString(lcPassword,"utf-8") * For versions of Chilkat < 10.0.0, use CreateObject('Chilkat_9_5_0.Crypt2') loCrypt = CreateObject('Chilkat.Crypt2') loCrypt.HashAlgorithm = "SHA-1" loCrypt.EncodingMode = "base64" * Note: The HashBdENC method is added in Chilkat v9.5.0.66 lcPasswordDigest = loCrypt.HashBdENC(loBd) loWsse.UpdateChildContent("wsse:UsernameToken|wsse:Password",lcPasswordDigest) * Examine the final SOAP XML with WS-Security header added. ? loXml.GetXml() RELEASE loXml RELEASE loWsse RELEASE loPrng RELEASE loBd RELEASE loDt RELEASE loCrypt |
© 2000-2025 Chilkat Software, Inc. All Rights Reserved.