Unicode C++
Unicode C++
PRODA Get OAuth2 Access Token using JWT
See more PRODA Examples
Demonstrates how to get an OAuth2 access token for the PRODA Australian Government Online Services using a JWT.Chilkat Unicode C++ Downloads
#include <CkPrivateKeyW.h>
#include <CkJwtW.h>
#include <CkJsonObjectW.h>
#include <CkHttpW.h>
#include <CkHttpRequestW.h>
#include <CkHttpResponseW.h>
void ChilkatSample(void)
{
bool success = false;
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// First create a JWT to be sent in the POST to https://vnd.proda.humanservices.gov.au/mga/sps/oauth/oauth20/token
CkPrivateKeyW privKey;
// Load an RSA private key from a PEM file.
// Chilkat provides alternative methods to load from other formats, or to load from a string or binary data.
success = privKey.LoadEncryptedPemFile(L"qa_data/pem/rsa_passwd.pem",L"passwd");
if (success == false) {
wprintf(L"%s\n",privKey.lastErrorText());
return;
}
CkJwtW jwt;
// Build the JOSE header
CkJsonObjectW jose;
// Use RS256. Pass the string "RS384" or "RS512" to use RSA with SHA-384 or SHA-512.
success = jose.AppendString(L"alg",L"RS256");
success = jose.AppendString(L"typ",L"JWT");
success = jose.AppendString(L"kid",L"test-device");
// Now build the JWT claims (also known as the payload)
CkJsonObjectW claims;
success = claims.AppendString(L"iss",L"9646844092");
success = claims.AppendString(L"sub",L"test-device");
success = claims.AppendString(L"aud",L"https://proda.humanservices.gov.au");
// Set the timestamp of when the JWT was created to now.
int curDateTime = jwt.GenNumericDate(0);
success = claims.AddIntAt(-1,L"iat",curDateTime);
// Set the timestamp defining an expiration time (end time) for the token
// to be now + 1 hour (3600 seconds)
success = claims.AddIntAt(-1,L"exp",curDateTime + 3600);
// Produce the smallest possible JWT:
jwt.put_AutoCompact(true);
// Create the JWT token. This is where the RSA signature is created.
const wchar_t *jwtToken = jwt.createJwtPk(jose.emit(),claims.emit(),privKey);
// ---------------------------------------------------------------------
// Build and send the POST, which should look something like this:
// POST https://vnd.proda.humanservices.gov.au/mga/sps/oauth/oauth20/token HTTP/1.1
// Content-Type: application/x-www-form-urlencoded
// Content-Length: 666
// Host: vnd.proda.humanservices.gov.au
//
// grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Ajwt-bearer&assertion=<jwt>&client_id=VendorClient03
CkHttpW http;
CkHttpRequestW req;
req.put_HttpVerb(L"POST");
req.put_ContentType(L"application/x-www-form-urlencoded");
// Add the request params.
req.AddParam(L"grant_type",L"urn:ietf:params:oauth:grant-type:jwt-bearer");
req.AddParam(L"assertion",jwtToken);
req.AddParam(L"client_id",L"VendorClient03");
CkHttpResponseW resp;
success = http.HttpReq(L"https://vnd.proda.humanservices.gov.au/mga/sps/oauth/oauth20/token",req,resp);
if (success == false) {
wprintf(L"%s\n",http.lastErrorText());
return;
}
wprintf(L"Response status code = %d\n",resp.get_StatusCode());
wprintf(L"Response body:\n");
wprintf(L"%s\n",resp.bodyStr());
}