Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Create JPK VAT metadata XML

See more RSA Examples

Demonstrates how to create the JPK VAT metadata XML (InitUpload) that will be signed using XADES.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // First build an InitUpload XML template

    // Use this online tool to generate the code from the sample XML below:
    // Generate Code to Create XML

    // <InitUpload xmlns="http://e-dokumenty.mf.gov.pl">
    //     <DocumentType>JPK</DocumentType>
    //     <Version>01.02.01.20160617</Version>
    //     <EncryptionKey algorithm="RSA" encoding="Base64" mode="ECB" padding="PKCS#1">F9EhKFec...uWqAWUIg==</EncryptionKey>
    //     <DocumentList>
    //         <Document>
    //             <FormCode schemaVersion="1-1" systemCode="JPK_VAT (3)">JPK_VAT</FormCode>
    //             <FileName>JPK_VAT_3_v1-1_20181201.xml</FileName>
    //             <ContentLength>8736</ContentLength>
    //             <HashValue algorithm="SHA-256" encoding="Base64">JFDI1pItwh6dj/Xe1uts/x61qnjZ4DLHpkZMhmf1oKQ=</HashValue>
    //             <FileSignatureList filesNumber="1">
    //                 <Packaging>
    //                     <SplitZip mode="zip" type="split"/>
    //                 </Packaging>
    //                 <Encryption>
    //                     <AES block="16" mode="CBC" padding="PKCS#7" size="256">
    //                         <IV bytes="16" encoding="Base64">z64oN9zXHt1+S3XACRSCYw==</IV>
    //                     </AES>
    //                 </Encryption>
    //                 <FileSignature>
    //                     <OrdinalNumber>1</OrdinalNumber>
    //                     <FileName>JPK_VAT_3_v1-1_20181201-000.xml.zip.aes</FileName>
    //                     <ContentLength>16</ContentLength>
    //                     <HashValue algorithm="MD5" encoding="Base64">5NX0q1935fvMjLFV7E1yDw==</HashValue>
    //                 </FileSignature>
    //             </FileSignatureList>
    //         </Document>
    //     </DocumentList>
    // </InitUpload>

    const xml = try chilkat.Xml.init();
    defer xml.deinit();
    xml.setTag("InitUpload");
    xml.addAttribute("xmlns", "http://e-dokumenty.mf.gov.pl") catch {};
    xml.updateChildContent("DocumentType", "JPK");
    xml.updateChildContent("Version", "01.02.01.20160617");
    xml.updateAttrAt("EncryptionKey", true, "algorithm", "RSA") catch {};
    xml.updateAttrAt("EncryptionKey", true, "encoding", "Base64") catch {};
    xml.updateAttrAt("EncryptionKey", true, "mode", "ECB") catch {};
    xml.updateAttrAt("EncryptionKey", true, "padding", "PKCS#1") catch {};
    xml.updateChildContent("EncryptionKey", "TO BE DETERMINED");
    xml.updateAttrAt("DocumentList|Document|FormCode", true, "schemaVersion", "1-1") catch {};
    xml.updateAttrAt("DocumentList|Document|FormCode", true, "systemCode", "JPK_VAT (3)") catch {};
    xml.updateChildContent("DocumentList|Document|FormCode", "JPK_VAT");
    xml.updateChildContent("DocumentList|Document|FileName", "JPK_VAT_3_v1-1_20181201.xml");
    xml.updateChildContent("DocumentList|Document|ContentLength", "9999");
    xml.updateAttrAt("DocumentList|Document|HashValue", true, "algorithm", "SHA-256") catch {};
    xml.updateAttrAt("DocumentList|Document|HashValue", true, "encoding", "Base64") catch {};
    xml.updateChildContent("DocumentList|Document|HashValue", "TO BE DETERMINED");
    xml.updateAttrAt("DocumentList|Document|FileSignatureList", true, "filesNumber", "1") catch {};
    xml.updateAttrAt("DocumentList|Document|FileSignatureList|Packaging|SplitZip", true, "mode", "zip") catch {};
    xml.updateAttrAt("DocumentList|Document|FileSignatureList|Packaging|SplitZip", true, "type", "split") catch {};
    xml.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "block", "16") catch {};
    xml.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "mode", "CBC") catch {};
    xml.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "padding", "PKCS#7") catch {};
    xml.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES", true, "size", "256") catch {};
    xml.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES|IV", true, "bytes", "16") catch {};
    xml.updateAttrAt("DocumentList|Document|FileSignatureList|Encryption|AES|IV", true, "encoding", "Base64") catch {};
    xml.updateChildContent("DocumentList|Document|FileSignatureList|Encryption|AES|IV", "TO BE DETERMINED");
    xml.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|OrdinalNumber", "1");
    xml.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|FileName", "JPK_VAT_3_v1-1_20181201-000.xml.zip.aes");
    xml.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|ContentLength", "9999");
    xml.updateAttrAt("DocumentList|Document|FileSignatureList|FileSignature|HashValue", true, "algorithm", "MD5") catch {};
    xml.updateAttrAt("DocumentList|Document|FileSignatureList|FileSignature|HashValue", true, "encoding", "Base64") catch {};
    xml.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|HashValue", "TO BE DETERMINED");

    // ------------------------------------------------------------
    // Step 1: Load our JPK_VAT XML and update the DocumentList|Document|HashValue
    // and DocumentList|Document|ContentLength
    const bd_xml = try chilkat.BinData.init();
    defer bd_xml.deinit();
    bd_xml.loadFile("qa_data/xml_dsig/jpk_vat/JPK_VAT_3_v1-1_20181201-000.xml") catch {
        std.debug.print("Failed to load XML file.\n", .{});
        return;
    };

    xml.updateChildContentInt("DocumentList|Document|ContentLength", bd_xml.getNumBytes());

    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();
    crypt.setHashAlgorithm("sha256");
    crypt.setEncodingMode("base64");
    xml.updateChildContent("DocumentList|Document|HashValue", try crypt.hashBdENC(alloc, bd_xml));

    // ------------------------------------------------------------
    // Step 2: Create a Zip archive containing the XML.
    const zip = try chilkat.Zip.init();
    defer zip.deinit();
    // The filename we pass here doesn't matter because we won't actually be creating a .zip file.
    zip.newZip("anything.zip") catch {};
    zip.addBd("JPK_VAT_3_v1-1_20181201-000.xml", bd_xml) catch {};
    // Write the .zip file to a BinData object.
    const bd_zip = try chilkat.BinData.init();
    defer bd_zip.deinit();
    zip.writeBd(bd_zip) catch {};

    // ------------------------------------------------------------
    // Step 3: Generate a random 256-bit AES key (32-bytes)
    const prng = try chilkat.Prng.init();
    defer prng.deinit();
    const bd_aes_key = try chilkat.BinData.init();
    defer bd_aes_key.deinit();
    prng.genRandomBd(32, bd_aes_key) catch {};
    const iv_bytes = try prng.genRandom(alloc, 16, "base64");

    // Store the IV (base64 string) in the XML.
    xml.updateChildContent("DocumentList|Document|FileSignatureList|Encryption|AES|IV", iv_bytes);

    // ------------------------------------------------------------
    // Step 4: AES encrypt our zip archive (the contents of bdZip)
    crypt.setCipherMode("cbc");
    crypt.setKeyLength(256);
    crypt.setCryptAlgorithm("aes");
    crypt.setPaddingScheme(0);
    crypt.setEncodedIV(iv_bytes, "base64");
    crypt.setEncodedKey(try bd_aes_key.getEncoded(alloc, "base64"), "base64");
    // AES by definition has a block size of 16.
    crypt.encryptBd(bd_zip) catch {};

    // bdZip now contains the AES encrypted data.
    // Note: This is NOT the same as a zip where the contents are AES encrypted.
    // In that case, we have an unencrypted zip structure with AES encrypted files within.
    // In our case, the entire zip file image is encrypted.

    // Save the bdZip to a file.  This is what will get sent to e-dokumenty.mf.gov.pl
    try bd_zip.writeFile("qa_output/JPK_VAT_3_v1-1_20181201-000.xml.zip.aes");
    xml.updateChildContentInt("DocumentList|Document|FileSignatureList|FileSignature|ContentLength", bd_zip.getNumBytes());

    // ------------------------------------------------------------
    // Step 4: RSA Encrypt the AES key using the public key certificate provided by the Ministry of Finance
    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    cert.loadFromFile("qa_data/pem/mf_public_rsa.pem") catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    const pub_key = try chilkat.PublicKey.init();
    defer pub_key.deinit();
    cert.getPublicKey(pub_key) catch {};

    const rsa = try chilkat.Rsa.init();
    defer rsa.deinit();
    rsa.usePublicKey(pub_key) catch {};

    rsa.setEncodingMode("base64");
    rsa.setLittleEndian(false);
    // in-place RSA encrypt the contents of bdAesKey.
    rsa.encryptBd(bd_aes_key, false) catch {};
    xml.updateChildContent("EncryptionKey", try bd_aes_key.getEncoded(alloc, "base64"));

    // Step 5: We forgot to get the MD5 hash of the AES encrypted zip.
    // (I'm assuming we need the MD5 of the encrypted zip as opposed to the MD5 of the pre-encrypted zip..)
    crypt.setHashAlgorithm("md5");
    xml.updateChildContent("DocumentList|Document|FileSignatureList|FileSignature|HashValue", try crypt.hashBdENC(alloc, bd_zip));

    // At this point, the XML is prepared and the AES encrypted image of the zip file is written
    // to a file (and also in bdZip).
    const final_xml = try xml.getXml(alloc);
    std.debug.print("{s}\n", .{final_xml});

    xml.saveXml("qa_output/jpk_vat.xml") catch {};

    std.debug.print("Finished.\n", .{});
}