Chilkat HOME Android™ AutoIt C C# C++ Chilkat2-Python CkPython Classic ASP DataFlex Delphi DLL Go Java Node.js Objective-C PHP Extension Perl PowerBuilder PowerShell PureBasic Ruby SQL Server Swift Tcl Unicode C Unicode C++ VB.NET VBScript Visual Basic 6.0 Visual FoxPro Xojo Plugin
(Tcl) SOAP WS-Security UsernameTokenDemonstrates how to add a UsernameToken with the WSS SOAP Message Security header. Note: This example requires Chilkat v9.5.0.66 or later.
load ./chilkat.dll # This example requires the Chilkat Crypt API to have been previously unlocked. # See Unlock Chilkat Crypt for sample code. # An HTTP SOAP request is an HTTP request where the SOAP XML composes the body. # This example demonstrates how to add a WS-Security header such as the following: # # <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="SecurityToken-6138db82-5a4c-4bf7-915f-af7a10d9ae96"> # <wsse:Username>user</wsse:Username> # <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">CBb7a2itQDgxVkqYnFtggUxtuqk=</wsse:Password> # <wsse:Nonce>5ABcqPZWb6ImI2E6tob8MQ==</wsse:Nonce> # <wsu:Created>2010-06-08T07:26:50Z</wsu:Created> # </wsse:UsernameToken> # # First build some simple SOAP XML that has some header and body. set xml [new_CkXml] CkXml_put_Tag $xml "env:Envelope" CkXml_AddAttribute $xml "xmlns:env" "http://www.w3.org/2003/05/soap-envelope" CkXml_UpdateAttrAt $xml "env:Header|n:alertcontrol" 1 "xmlns:n" "http://example.org/alertcontrol" CkXml_UpdateChildContent $xml "env:Header|n:alertcontrol|n:priority" "1" CkXml_UpdateChildContent $xml "env:Header|n:alertcontrol|n:expires" "2001-06-22T14:00:00-05:00" CkXml_UpdateAttrAt $xml "env:Body|m:alert" 1 "xmlns:m" "http://example.org/alert" CkXml_UpdateChildContent $xml "env:Body|m:alert|m:msg" "Pick up Mary at school at 2pm" puts [CkXml_getXml $xml] puts "----" # The following SOAP XML is built: # <env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope"> # <env:Header> # <n:alertcontrol xmlns:n="http://example.org/alertcontrol"> # <n:priority>1</n:priority> # <n:expires>2001-06-22T14:00:00-05:00</n:expires> # </n:alertcontrol> # </env:Header> # <env:Body> # <m:alert xmlns:m="http://example.org/alert"> # <m:msg>Pick up Mary at school at 2pm</m:msg> # </m:alert> # </env:Body> # </env:Envelope> # # Now build the WSSE XML housing that we'll insert into the above SOAP XML at the end. # <wsse:Security> # <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="WSU_ID"> # <wsse:Username>USERNAME</wsse:Username> # <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">PASSWORD_DIGEST</wsse:Password> # <wsse:Nonce>NONCE</wsse:Nonce> # <wsu:Created>CREATED</wsu:Created> # </wsse:UsernameToken> # </wsse:Security> set wsse [new_CkXml] CkXml_put_Tag $wsse "wsse:Security" CkXml_UpdateAttrAt $wsse "wsse:UsernameToken" 1 "xmlns:wsu" "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" CkXml_UpdateAttrAt $wsse "wsse:UsernameToken" 1 "wsu:Id" "WSU_ID" CkXml_UpdateChildContent $wsse "wsse:UsernameToken|wsse:Username" "USERNAME" CkXml_UpdateAttrAt $wsse "wsse:UsernameToken|wsse:Password" 1 "Type" "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest" CkXml_UpdateChildContent $wsse "wsse:UsernameToken|wsse:Password" "PASSWORD_DIGEST" CkXml_UpdateChildContent $wsse "wsse:UsernameToken|wsse:Nonce" "NONCE" CkXml_UpdateChildContent $wsse "wsse:UsernameToken|wsu:Created" "CREATED" puts [CkXml_getXml $wsse] puts "----" # Insert the wsse:Security XML into the existing SOAP header: # xHeader is a CkXml set xHeader [CkXml_GetChildWithTag $xml "env:Header"] CkXml_AddChildTree $xHeader $wsse delete_CkXml $xHeader # Now show the SOAP XML with the wsse:Security header added: puts [CkXml_getXml $xml] puts "----" # Now our XML looks like this: # <env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope"> # <env:Header> # <n:alertcontrol xmlns:n="http://example.org/alertcontrol"> # <n:priority>1</n:priority> # <n:expires>2001-06-22T14:00:00-05:00</n:expires> # </n:alertcontrol> # <wsse:Security> # <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="WSU_ID"> # <wsse:Username>USERNAME</wsse:Username> # <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">PASSWORD_DIGEST</wsse:Password> # <wsse:Nonce>NONCE</wsse:Nonce> # <wsu:Created>CREATED</wsu:Created> # </wsse:UsernameToken> # </wsse:Security> # </env:Header> # <env:Body> # <m:alert xmlns:m="http://example.org/alert"> # <m:msg>Pick up Mary at school at 2pm</m:msg> # </m:alert> # </env:Body> # </env:Envelope> # # ----------------------------------------------------- # Now let's fill-in-the-blanks with actual information... # ----------------------------------------------------- set wsu_id "Example-1" CkXml_UpdateAttrAt $wsse "wsse:UsernameToken" 1 "wsu:Id" $wsu_id set password "password" set username "user" CkXml_UpdateChildContent $wsse "wsse:UsernameToken|wsse:Username" $username # The nonce should be 16 random bytes. set prng [new_CkPrng] set bd [new_CkBinData] # Generate 16 random bytes into bd. # Note: The GenRandomBd method is added in Chilkat v9.5.0.66 CkPrng_GenRandomBd $prng 16 $bd set nonce [CkBinData_getEncoded $bd "base64"] CkXml_UpdateChildContent $wsse "wsse:UsernameToken|wsse:Nonce" $nonce # Get the current date/time in a string with this format: 2010-06-08T07:26:50Z set dt [new_CkDateTime] CkDateTime_SetFromCurrentSystemTime $dt set bLocal 0 set created [CkDateTime_getAsTimestamp $dt $bLocal] CkXml_UpdateChildContent $wsse "wsse:UsernameToken|wsu:Created" $created # The password digest is calculated like this: # Password_Digest = Base64 ( SHA-1 ( nonce + created + password ) ) CkBinData_AppendString $bd $created "utf-8" CkBinData_AppendString $bd $password "utf-8" set crypt [new_CkCrypt2] CkCrypt2_put_HashAlgorithm $crypt "SHA-1" CkCrypt2_put_EncodingMode $crypt "base64" # Note: The HashBdENC method is added in Chilkat v9.5.0.66 set passwordDigest [CkCrypt2_hashBdENC $crypt $bd] CkXml_UpdateChildContent $wsse "wsse:UsernameToken|wsse:Password" $passwordDigest # Examine the final SOAP XML with WS-Security header added. puts [CkXml_getXml $xml] delete_CkXml $xml delete_CkXml $wsse delete_CkPrng $prng delete_CkBinData $bd delete_CkDateTime $dt delete_CkCrypt2 $crypt |
© 2000-2025 Chilkat Software, Inc. All Rights Reserved.