Chilkat HOME Android™ AutoIt C C# C++ Chilkat2-Python CkPython Classic ASP DataFlex Delphi DLL Go Java Node.js Objective-C PHP Extension Perl PowerBuilder PowerShell PureBasic Ruby SQL Server Swift Tcl Unicode C Unicode C++ VB.NET VBScript Visual Basic 6.0 Visual FoxPro Xojo Plugin
(Swift) Xero OAuth1 Authorization (3-legged)Demonstrates 3-legged OAuth1 authorization for Xero
func chilkatTest() { var consumerKey: String? = "XERO_CONSUMER_KEY" var consumerSecret: String? = "XERO_CONSUMER_SECRET" var requestTokenUrl: String? = "https://api.xero.com/oauth/RequestToken" var authorizeUrl: String? = "https://api.xero.com/oauth/Authorize" var accessTokenUrl: String? = "https://api.xero.com/oauth/AccessToken" // The port number is picked at random. It's some unused port that won't likely conflict with anything else.. var callbackUrl: String? = "http://localhost:3017/" var callbackLocalPort: Int = 3017 // The 1st step in 3-legged OAuth1.0a is to send a POST to the request token URL to obtain an OAuth Request Token let http = CkoHttp()! var success: Bool http.oAuth1 = true http.oAuthConsumerKey = consumerKey http.oAuthConsumerSecret = consumerSecret http.oAuthCallback = callbackUrl let req = CkoHttpRequest()! var resp: CkoHttpResponse? = http.postUrlEncoded(requestTokenUrl, req: req) if http.lastMethodSuccess != true { print("\(http.lastErrorText!)") return } // If successful, the resp.BodyStr contains something like this: // oauth_token=-Wa_KwAAAAAAxfEPAAABV8Qar4Q&oauth_token_secret=OfHY4tZBX2HK4f7yIw76WYdvnl99MVGB&oauth_callback_confirmed=true print("\(resp!.bodyStr!)") let hashTab = CkoHashtable()! hashTab.addQueryParams(resp!.bodyStr) var requestToken: String? = hashTab.lookupStr("oauth_token") var requestTokenSecret: String? = hashTab.lookupStr("oauth_token_secret") http.oAuthTokenSecret = requestTokenSecret resp = nil print("oauth_token = \(requestToken!)") print("oauth_token_secret = \(requestTokenSecret!)") // --------------------------------------------------------------------------- // The next step is to form a URL to send to the authorizeUrl // This is an HTTP GET that we load into a popup browser. let sbUrlForBrowser = CkoStringBuilder()! sbUrlForBrowser.append(authorizeUrl) sbUrlForBrowser.append("?oauth_token=") sbUrlForBrowser.append(requestToken) var urlForBrowser: String? = sbUrlForBrowser.getAsString() // When the urlForBrowser is loaded into a browser, the response from Xero will redirect back to localhost:3017 // We'll need to start a socket that is listening on port 3017 for the callback from the browser. let listenSock = CkoSocket()! var backLog: Int = 5 success = listenSock.bindAndListen(callbackLocalPort, backlog: backLog) if success != true { print("\(listenSock.lastErrorText!)") return } // Wait for the browser's connection in a background thread. // (We'll send load the URL into the browser following this..) // Wait a max of 60 seconds before giving up. var maxWaitMs: Int = 60000 var task: CkoTask? = listenSock.acceptNextConnectionAsync(maxWaitMs) task!.run() // At this point, your application should load the URL in a browser. // For example, // in C#: System.Diagnostics.Process.Start(urlForBrowser); // in Java: Desktop.getDesktop().browse(new URI(urlForBrowser)); // in VBScript: Set wsh=WScript.CreateObject("WScript.Shell") // wsh.Run urlForBrowser // in Xojo: ShowURL(url) (see http://docs.xojo.com/index.php/ShowURL) // in Dataflex: Runprogram Background "c:\Program Files\Internet Explorer\iexplore.exe" sUrl // The Xero account owner would interactively accept or deny the authorization request. // Add the code to load the url in a web browser here... // Add the code to load the url in a web browser here... // Add the code to load the url in a web browser here... // System.Diagnostics.Process.Start(urlForBrowser); // Wait for the listenSock's task to complete. success = task!.wait(maxWaitMs) if !success || (task!.statusInt.intValue != 7) || (task!.taskSuccess != true) { if !success { // The task.LastErrorText applies to the Wait method call. print("\(task!.lastErrorText!)") } else { // The ResultErrorText applies to the underlying task method call (i.e. the AcceptNextConnection) print("\(task!.status!)") print("\(task!.resultErrorText!)") } task = nil return } // If we get to this point, the connection from the browser arrived and was accepted. // We no longer need the listen socket... // Stop listening on port 3017. listenSock.close(10) // First get the connected socket. let sock = CkoSocket()! sock.loadTaskResult(task) task = nil // Read the start line of the request.. var startLine: String? = sock.receive(untilMatch: "\r\n") if sock.lastMethodSuccess != true { print("\(sock.lastErrorText!)") return } // Read the request header. var requestHeader: String? = sock.receive(untilMatch: "\r\n\r\n") if sock.lastMethodSuccess != true { print("\(sock.lastErrorText!)") return } // The browser SHOULD be sending us a GET request, and therefore there is no body to the request. // Once the request header is received, we have all of it. // We can now send our HTTP response. let sbResponseHtml = CkoStringBuilder()! sbResponseHtml.append("<html><body><p>Chilkat thanks you!</b></body</html>") let sbResponse = CkoStringBuilder()! sbResponse.append("HTTP/1.1 200 OK\r\n") sbResponse.append("Content-Length: ") sbResponse.appendInt(sbResponseHtml.length.intValue) sbResponse.append("\r\n") sbResponse.append("Content-Type: text/html\r\n") sbResponse.append("\r\n") sbResponse.appendSb(sbResponseHtml) sock.send(sbResponse.getAsString()) sock.close(50) // The information we need is in the startLine. // For example, the startLine will look something like this: // GET /?oauth_token=abcdRQAAZZAAxfBBAAABVabcd_k&oauth_verifier=9rdOq5abcdCe6cn8M3jabcdj3Eabcd&org=mUkIZabcdKEababcd189t0 HTTP/1.1 let sbStartLine = CkoStringBuilder()! sbStartLine.append(startLine) var numReplacements: Int = sbStartLine.replace("GET /?", replacement: "").intValue numReplacements = sbStartLine.replace(" HTTP/1.1", replacement: "").intValue sbStartLine.trim() // oauth_token=abcdRQAAZZAAxfBBAAABVabcd_k&oauth_verifier=9rdOq5abcdCe6cn8M3jabcdj3Eabcd&org=mUkIZabcdKEababcd189t0 print("startline: \(sbStartLine.getAsString()!)") hashTab.clear() hashTab.addQueryParams(sbStartLine.getAsString()) requestToken = hashTab.lookupStr("oauth_token") var authVerifier: String? = hashTab.lookupStr("oauth_verifier") // ------------------------------------------------------------------------------ // Finally , we must exchange the OAuth Request Token for an OAuth Access Token. http.oAuthToken = requestToken http.oAuthVerifier = authVerifier resp = http.postUrlEncoded(accessTokenUrl, req: req) if http.lastMethodSuccess != true { print("\(http.lastErrorText!)") return } // Make sure a successful response was received. if resp!.statusCode.intValue != 200 { print("\(resp!.statusLine!)") print("\(resp!.header!)") print("\(resp!.bodyStr!)") return } // If successful, the resp.BodyStr contains something like this: // oauth_token=85123455-fF41296Bi3daM8eCo9Y5vZabcdxXpRv864plYPOjr&oauth_token_secret=afiYJOgabcdSfGae7BDvJVVTwys8fUGpra5guZxbmFBZo&oauth_expires_in=1800&xero_org_muid=abcdecNhPKabcdNjz189t0 print("\(resp!.bodyStr!)") hashTab.clear() hashTab.addQueryParams(resp!.bodyStr) var accessToken: String? = hashTab.lookupStr("oauth_token") var accessTokenSecret: String? = hashTab.lookupStr("oauth_token_secret") var orgMuid: String? = hashTab.lookupStr("xero_org_muid") var expiresIn: String? = hashTab.lookupStr("oauth_expires_in") resp = nil // The access token + secret is what should be saved and used for // subsequent REST API calls. print("Access Token = \(accessToken!)") print("Access Token Secret = \(accessTokenSecret!)") print("xero_org_muid = \(orgMuid!)") print("oauth_expires_in = \(expiresIn!)") // Save this access token for future calls. // Just in case we need xero_org_muid and oauth_expires_in, save those also.. let json = CkoJsonObject()! json.append("oauth_token", value: accessToken) json.append("oauth_token_secret", value: accessTokenSecret) json.append("xero_org_muid", value: orgMuid) json.append("oauth_expires_in", value: expiresIn) let fac = CkoFileAccess()! fac.writeEntireTextFile("qa_data/tokens/xero.json", fileData: json.emit(), charset: "utf-8", includePreamble: false) print("Success.") } |
© 2000-2025 Chilkat Software, Inc. All Rights Reserved.