Sample code for 30+ languages & platforms
Swift

SharePoint -- Get Server Form Digest Value

Demonstrates how to get a server form digest value to be placed in the X-RequestDigest HTTP request header for POST, PUT, MERGE, and DELETE requests. A form digest value is typically valid for 1800 seconds (i.e. 30 minutes). This example persists the value to a file, and only requests a new form digest value if the existing one is near expiration.

Chilkat Swift Downloads

Swift

func chilkatTest() {
    var success: Bool = false

    // This requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // First, let's see if we already have a persisted form digest value
    // that hasn't yet expired.
    let fac = CkoFileAccess()!
    let xml = CkoXml()!

    // My example code (below) persists the form digest XML in this format:
    // 
    // 	<savedFormDigestValue>
    // 	<d:ExpireDateTime>2017-04-12T20:46:39Z</d:ExpireDateTime>
    // 	<d:FormDigestValue>0x3059FFB920651834540F3E6792EA73F5746B302E953FF4E808E485DB1E6C2836C7CF924644995F092453B02A94DE14A7962674B7B16780AF16EAFB8C246BCDC7,12 Apr 2017 17:08:22 -0000</d:FormDigestValue>
    // 	</savedFormDigestValue>
    // 

    let dtExpire = CkoDateTime()!
    let dtNow = CkoDateTime()!

    var formDigestXmlFile: String? = "qa_data/sharepoint/savedFormDigestValue.xml"
    if fac.fileExists(path: formDigestXmlFile) == true {

        xml.loadFile(path: formDigestXmlFile)

        // Get the expire date/time
        dtExpire.set(fromTimestamp: xml.getChildContent(tagPath: "d:ExpireDateTime"))

        // Get the current date/time
        dtNow.setFromCurrentSystemTime()

        // Get both times as Unix time values
        var tNow: Int = dtNow.get(asUnixTime: false)
        var tExpire: Int = dtExpire.get(asUnixTime: false)

        // If tNow >= tExpire, then fall through.
        // Otherwise, just use the cached digest value.
        if tNow < tExpire {
            print("Cached digest value is not yet expired.")
            print("X-RequestDigest: \(xml.getChildContent(tagPath: "d:FormDigestValue")!)")
            return
        }

    }

    // If we got to this point, the cached digest value either does not exist, or expired.

    let http = CkoHttp()!

    // If SharePoint Windows classic authentication is used, then set the 
    // Login, Password, LoginDomain, and NtlmAuth properties.
    http.login = "SHAREPOINT_USERNAME"
    http.password = "SHAREPOINT_PASSWORD"
    http.loginDomain = "SHAREPOINT_NTLM_DOMAIN"
    http.ntlmAuth = true

    // The more common case is to use SharePoint Online authentication (via the SPOIDCRL cookie).
    // If so, do not set Login, Password, LoginDomain, and NtlmAuth, and instead
    // establish the cookie as shown at SharePoint Online Authentication

    // When creating, updating, and deleting SharePoint entities, we'll need
    // to first get the server's form digest value to send in the X-RequestDigest header.
    // This can be retrieved by making a POST request with an empty body to
    // http://<site url>/_api/contextinfo and extracting the value of the
    // d:FormDigestValue node in the XML that the contextinfo endpoint returns.

    // Apparently, SharePoint needs an "Accept" request header equal to "application/xml",
    // otherwise SharePoint will return an utterly incomprehensible and useless error message.
    var savedAccept: String? = http.accept
    http.accept = "application/xml"

    // Note: The last argument ("utf-8") is meaningless here because the body is empty.
    let resp = CkoHttpResponse()!
    success = http.httpStr(verb: "POST", url: "https://SHAREPOINT_HTTPS_DOMAIN/_api/contextinfo", bodyStr: "", charset: "utf-8", contentType: "application/xml", response: resp)
    if success == false {
        print("\(http.lastErrorText!)")
        return
    }

    // Restore the default Accept header
    http.accept = savedAccept

    if resp.statusCode.intValue != 200 {
        // A response status code not equal to 200 indicates failure.
        print("Response status code = \(resp.statusCode.intValue)")
        print("Response body:")
        print("\(resp.bodyStr!)")
        return
    }

    xml.load(xmlData: resp.bodyStr)

    // The response XML looks like this:

    // <?xml version="1.0" encoding="utf-8" ?>
    // <d:GetContextWebInformation xmlns:d="http://schemas.microsoft.com/ado/2007/08/dataservices" xmlns:m="http://schemas.microsoft.com/ado/2007/08/dataservices/metadata" xmlns:georss="http://www.georss.org/georss" xmlns:gml="http://www.opengis.net/gml" m:type="SP.ContextWebInformation">
    //     <d:FormDigestTimeoutSeconds m:type="Edm.Int32">1800</d:FormDigestTimeoutSeconds>
    //     <d:FormDigestValue>0x3059FFB920651834540F3E6792EA73F5746B302E953FF4E808E485DB1E6C2836C7CF924644995F092453B02A94DE14A7962674B7B16780AF16EAFB8C246BCDC7,12 Apr 2017 17:08:22 -0000</d:FormDigestValue>
    //     <d:LibraryVersion>15.0.4569.1000</d:LibraryVersion>
    //     <d:SiteFullUrl>https://SHAREPOINT_HTTPS_DOMAIN</d:SiteFullUrl>
    //     <d:SupportedSchemaVersions m:type="Collection(Edm.String)">
    //         <d:element>14.0.0.0</d:element>
    //         <d:element>15.0.0.0</d:element>
    //     </d:SupportedSchemaVersions>
    //     <d:WebFullUrl>https://SHAREPOINT_HTTPS_DOMAIN</d:WebFullUrl>
    // </d:GetContextWebInformation>
    // 

    // Cache the digest value, and also an expiration time.  If this code is run again
    // before the digest expires, we'll just get it from the file.
    let xml2 = CkoXml()!

    xml2.tag = "savedFormDigestValue"
    xml2.newChild2(tagPath: "d:FormDigestValue", content: xml.getChildContent(tagPath: "d:FormDigestValue"))

    var timeoutInSec: Int = xml.getChildIntValue(tagPath: "d:FormDigestTimeoutSeconds").intValue
    print("Timeout in seconds = \(timeoutInSec)")

    // Convert this to an expire timestamp.
    // Let's make it expire 30 seconds prior to the actual timeout, just to be safe.
    if timeoutInSec > 30 {
        timeoutInSec = timeoutInSec - 30
    }

    dtExpire.setFromCurrentSystemTime()
    dtExpire.addSeconds(numSeconds: timeoutInSec)
    xml2.newChild2(tagPath: "d:ExpireDateTime", content: dtExpire.get(asTimestamp: false))

    // Persist the digest and expire time to a file.
    xml2.save(path: formDigestXmlFile)

    print("Here is the new form digest value:")
    print("X-RequestDigest: \(xml.getChildContent(tagPath: "d:FormDigestValue")!)")

}