Sample code for 30+ languages & platforms
Zig

Alliance Access LAU Sign Message (XML Signature using HMAC-SHA-256)

See more XML Digital Signatures Examples

Demonstrates how to sign XML according to the requirements for Alliance Access LAU (Local Authentication) using HMAC-SHA-256.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // We begin with this message:

    // <?xml version="1.0" encoding="utf-8"?>
    // <Saa:DataPDU xmlns:Saa="urn:swift:saa:xsd:saa.2.0" xmlns:Sw="urn:swift:snl:ns.Sw"
    //   xmlns:SwGbl="urn:swift:snl:ns.SwGbl" xmlns:SwInt="urn:swift:snl:ns:SwInt" xmlns:SwSec="url:swift:snl:ns.SwSec">
    //     <Saa:Revision>2.0.7</Saa:Revision>
    //     <Saa:Header>
    //         <Saa:Message>
    //             <test>blah blah</test>
    //         </Saa:Message>
    //     </Saa:Header>
    //     <Saa:Body>...</Saa:Body>
    //     <Saa:LAU>
    //     </Saa:LAU>
    // </Saa:DataPDU>

    // And we want so sign to create this as the result:
    // The signed XML we'll create will not be indented and pretty-printed like this.
    // Instead, we'll use the "CompactSignedXml" behavior to produce compact single-line XML.

    // <?xml version="1.0" encoding="utf-8"?>
    // <Saa:DataPDU xmlns:Saa="urn:swift:saa:xsd:saa.2.0" xmlns:Sw="urn:swift:snl:ns.Sw"
    //   xmlns:SwGbl="urn:swift:snl:ns.SwGbl" xmlns:SwInt="urn:swift:snl:ns:SwInt" xmlns:SwSec="url:swift:snl:ns.SwSec">
    //     <Saa:Revision>2.0.7</Saa:Revision>
    //     <Saa:Header>
    //         <Saa:Message>
    //             <test>blah blah</test>
    //         </Saa:Message>
    //     </Saa:Header>
    //     <Saa:Body>...</Saa:Body>
    //     <Saa:LAU>
    //         <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
    //             <ds:SignedInfo>
    //                 <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
    //                 <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#hmac-sha256"/>
    //                 <ds:Reference URI="">
    //                     <ds:Transforms>
    //                         <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
    //                         <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
    //                     </ds:Transforms>
    //                     <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
    //                     <ds:DigestValue>Y7oScHnYOUQvni/TSzZbDec+HR+mWIFH149GXpwj1Ws=</ds:DigestValue>
    //                 </ds:Reference>
    //             </ds:SignedInfo>
    //             <ds:SignatureValue>6ynF/FcwbPsHrtlj3h2agJigdnvpbO6hOzKSRGzqkw0=</ds:SignatureValue>
    //         </ds:Signature>
    //     </Saa:LAU>
    // </Saa:DataPDU>

    // Create the XML to be signed...

    // (The XML does not need to be created this way.  It can be loaded from a file or a string.)
    // Also, use this online tool to generate code from sample XML:
    // Generate Code to Create XML

    const xml_to_sign = try chilkat.Xml.init();
    defer xml_to_sign.deinit();
    xml_to_sign.setTag("Saa:DataPDU");
    xml_to_sign.addAttribute("xmlns:Saa", "urn:swift:saa:xsd:saa.2.0") catch {};
    xml_to_sign.addAttribute("xmlns:Sw", "urn:swift:snl:ns.Sw") catch {};
    xml_to_sign.addAttribute("xmlns:SwGbl", "urn:swift:snl:ns.SwGbl") catch {};
    xml_to_sign.addAttribute("xmlns:SwInt", "urn:swift:snl:ns:SwInt") catch {};
    xml_to_sign.addAttribute("xmlns:SwSec", "url:swift:snl:ns.SwSec") catch {};
    xml_to_sign.updateChildContent("Saa:Revision", "2.0.7");
    xml_to_sign.updateChildContent("Saa:Header|Saa:Message|test", "blah blah");
    xml_to_sign.updateChildContent("Saa:Body", "...");
    xml_to_sign.updateChildContent("Saa:LAU", "");

    const gen = try chilkat.XmlDSigGen.init();
    defer gen.deinit();

    gen.setSigLocation("Saa:DataPDU|Saa:LAU");
    gen.setSigLocationMod(0);
    gen.setSigNamespacePrefix("ds");
    gen.setSigNamespaceUri("http://www.w3.org/2000/09/xmldsig#");
    gen.setSignedInfoCanonAlg("EXCL_C14N");
    gen.setSignedInfoDigestMethod("sha256");

    // You may alternatively choose "IndentedSignature" instead of "CompactSignedXml"
    gen.setBehaviors("CompactSignedXml");

    gen.addSameDocRef("", "sha256", "EXCL_C14N", "", "") catch {};

    // Specify the HMAC key.
    // For example, if the HMAC key is to be the us-ascii bytes of the string "secret",
    // the HMAC key can be set in any of the following ways (and also more ways not shown here..)
    gen.setHmacKey("secret", "ascii") catch {};
    // or
    gen.setHmacKey("c2VjcmV0", "base64") catch {};
    // or
    gen.setHmacKey("736563726574", "hex") catch {};

    // Sign the XML..
    const sb_xml = try chilkat.StringBuilder.init();
    defer sb_xml.deinit();
    xml_to_sign.getXmlSb(sb_xml) catch {};
    gen.createXmlDSigSb(sb_xml) catch {
        std.debug.print("{s}\n", .{try gen.getLastErrorText(alloc)});
        return;
    };

    // Save the signed XML to a file.
    try sb_xml.writeFile("qa_output/signedXml.xml", "utf-8", false);

    // Show the signed XML.
    std.debug.print("{s}\n", .{try sb_xml.getAsString(alloc)});
}