Xbase++
Xbase++
SOAP WS-Security UsernameToken
See more XML Examples
Demonstrates how to add a UsernameToken with the WSS SOAP Message Security header.Note: This example requires Chilkat v9.5.0.66 or later.
Chilkat Xbase++ Downloads
LOCAL oXml
LOCAL oWsse
LOCAL oXHeader
LOCAL cWsu_id
LOCAL cPassword
LOCAL cUsername
LOCAL oPrng
LOCAL oBd
LOCAL cNonce
LOCAL oDt
LOCAL nBLocal
LOCAL cCreated
LOCAL oCrypt
LOCAL cPasswordDigest
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// An HTTP SOAP request is an HTTP request where the SOAP XML composes the body.
// This example demonstrates how to add a WS-Security header such as the following:
//
// <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="SecurityToken-6138db82-5a4c-4bf7-915f-af7a10d9ae96">
// <wsse:Username>user</wsse:Username>
// <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">CBb7a2itQDgxVkqYnFtggUxtuqk=</wsse:Password>
// <wsse:Nonce>5ABcqPZWb6ImI2E6tob8MQ==</wsse:Nonce>
// <wsu:Created>2010-06-08T07:26:50Z</wsu:Created>
// </wsse:UsernameToken>
//
// First build some simple SOAP XML that has some header and body.
oXml := CreateObject("Chilkat.Xml")
oXml:Tag := "env:Envelope"
oXml:AddAttribute("xmlns:env", "http://www.w3.org/2003/05/soap-envelope")
oXml:UpdateAttrAt("env:Header|n:alertcontrol", 1, "xmlns:n", "http://example.org/alertcontrol")
oXml:UpdateChildContent("env:Header|n:alertcontrol|n:priority", "1")
oXml:UpdateChildContent("env:Header|n:alertcontrol|n:expires", "2001-06-22T14:00:00-05:00")
oXml:UpdateAttrAt("env:Body|m:alert", 1, "xmlns:m", "http://example.org/alert")
oXml:UpdateChildContent("env:Body|m:alert|m:msg", "Pick up Mary at school at 2pm")
? oXml:GetXml()
? "----"
// The following SOAP XML is built:
// <env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope">
// <env:Header>
// <n:alertcontrol xmlns:n="http://example.org/alertcontrol">
// <n:priority>1</n:priority>
// <n:expires>2001-06-22T14:00:00-05:00</n:expires>
// </n:alertcontrol>
// </env:Header>
// <env:Body>
// <m:alert xmlns:m="http://example.org/alert">
// <m:msg>Pick up Mary at school at 2pm</m:msg>
// </m:alert>
// </env:Body>
// </env:Envelope>
//
// Now build the WSSE XML housing that we'll insert into the above SOAP XML at the end.
// <wsse:Security>
// <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="WSU_ID">
// <wsse:Username>USERNAME</wsse:Username>
// <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">PASSWORD_DIGEST</wsse:Password>
// <wsse:Nonce>NONCE</wsse:Nonce>
// <wsu:Created>CREATED</wsu:Created>
// </wsse:UsernameToken>
// </wsse:Security>
oWsse := CreateObject("Chilkat.Xml")
oWsse:Tag := "wsse:Security"
oWsse:UpdateAttrAt("wsse:UsernameToken", 1, "xmlns:wsu", "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd")
oWsse:UpdateAttrAt("wsse:UsernameToken", 1, "wsu:Id", "WSU_ID")
oWsse:UpdateChildContent("wsse:UsernameToken|wsse:Username", "USERNAME")
oWsse:UpdateAttrAt("wsse:UsernameToken|wsse:Password", 1, "Type", "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest")
oWsse:UpdateChildContent("wsse:UsernameToken|wsse:Password", "PASSWORD_DIGEST")
oWsse:UpdateChildContent("wsse:UsernameToken|wsse:Nonce", "NONCE")
oWsse:UpdateChildContent("wsse:UsernameToken|wsu:Created", "CREATED")
? oWsse:GetXml()
? "----"
// Insert the wsse:Security XML into the existing SOAP header:
oXHeader := oXml:GetChildWithTag("env:Header")
oXHeader:AddChildTree(oWsse)
oXHeader:destroy()
// Now show the SOAP XML with the wsse:Security header added:
? oXml:GetXml()
? "----"
// Now our XML looks like this:
// <env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope">
// <env:Header>
// <n:alertcontrol xmlns:n="http://example.org/alertcontrol">
// <n:priority>1</n:priority>
// <n:expires>2001-06-22T14:00:00-05:00</n:expires>
// </n:alertcontrol>
// <wsse:Security>
// <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="WSU_ID">
// <wsse:Username>USERNAME</wsse:Username>
// <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">PASSWORD_DIGEST</wsse:Password>
// <wsse:Nonce>NONCE</wsse:Nonce>
// <wsu:Created>CREATED</wsu:Created>
// </wsse:UsernameToken>
// </wsse:Security>
// </env:Header>
// <env:Body>
// <m:alert xmlns:m="http://example.org/alert">
// <m:msg>Pick up Mary at school at 2pm</m:msg>
// </m:alert>
// </env:Body>
// </env:Envelope>
//
// -----------------------------------------------------
// Now let's fill-in-the-blanks with actual information...
// -----------------------------------------------------
cWsu_id := "Example-1"
oWsse:UpdateAttrAt("wsse:UsernameToken", 1, "wsu:Id", cWsu_id)
cPassword := "password"
cUsername := "user"
oWsse:UpdateChildContent("wsse:UsernameToken|wsse:Username", cUsername)
// The nonce should be 16 random bytes.
oPrng := CreateObject("Chilkat.Prng")
oBd := CreateObject("Chilkat.BinData")
// Generate 16 random bytes into bd.
// Note: The GenRandomBd method is added in Chilkat v9.5.0.66
oPrng:GenRandomBd(16, oBd)
cNonce := oBd:GetEncoded("base64")
oWsse:UpdateChildContent("wsse:UsernameToken|wsse:Nonce", cNonce)
// Get the current date/time in a string with this format: 2010-06-08T07:26:50Z
oDt := CreateObject("Chilkat.CkDateTime")
oDt:SetFromCurrentSystemTime()
nBLocal := 0
cCreated := oDt:GetAsTimestamp(nBLocal)
oWsse:UpdateChildContent("wsse:UsernameToken|wsu:Created", cCreated)
// The password digest is calculated like this:
// Password_Digest = Base64 ( SHA-1 ( nonce + created + password ) )
oBd:AppendString(cCreated, "utf-8")
oBd:AppendString(cPassword, "utf-8")
oCrypt := CreateObject("Chilkat.Crypt2")
oCrypt:HashAlgorithm := "SHA-1"
oCrypt:EncodingMode := "base64"
// Note: The HashBdENC method is added in Chilkat v9.5.0.66
cPasswordDigest := oCrypt:HashBdENC(oBd)
oWsse:UpdateChildContent("wsse:UsernameToken|wsse:Password", cPasswordDigest)
// Examine the final SOAP XML with WS-Security header added.
? oXml:GetXml()
oXml:destroy()
oWsse:destroy()
oPrng:destroy()
oBd:destroy()
oDt:destroy()
oCrypt:destroy()