Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Belgium eHealth Platform - checkAccessControl

See more Belgian eHealth Platform Examples

Demonstrates the checkAccessControl operation of PlatformIntegrationConsumerTest, which requires an X.509 certificate and signature. This tests the validity of your certificate and signature.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example assumes the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // Provide a certificate + private key.
    // Note: If your certificate + private key is located on a hardware token or smartcard, you can call a different function to load from smartcard..
    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    cert.loadPfxFile("SSIN=12345678.acc.p12", "p12_password") catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    // Create the XML to be signed...
    const xml_to_sign = try chilkat.Xml.init();
    defer xml_to_sign.deinit();
    xml_to_sign.setTag("soapenv:Envelope");
    xml_to_sign.addAttribute("xmlns:soapenv", "http://schemas.xmlsoap.org/soap/envelope/") catch {};
    xml_to_sign.addAttribute("xmlns:urn", "urn:be:fgov:ehealth:platformintegrationconsumertest:v1") catch {};
    xml_to_sign.addAttribute("xmlns:urn1", "urn:be:fgov:ehealth:platformintegrationconsumertest:types:v1") catch {};
    xml_to_sign.updateAttrAt("soapenv:Header|wsse:Security", true, "xmlns:wsse", "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd") catch {};
    xml_to_sign.updateAttrAt("soapenv:Header|wsse:Security", true, "xmlns:wsu", "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd") catch {};
    xml_to_sign.updateAttrAt("soapenv:Header|wsse:Security|wsse:BinarySecurityToken", true, "EncodingType", "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary") catch {};
    xml_to_sign.updateAttrAt("soapenv:Header|wsse:Security|wsse:BinarySecurityToken", true, "ValueType", "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-x509-token-profile-1.0#X509v3") catch {};
    xml_to_sign.updateAttrAt("soapenv:Header|wsse:Security|wsse:BinarySecurityToken", true, "wsu:Id", "X509-FC77E2C72083DA8E0F16711753508182856") catch {};

    // ---------------------------------------------------------------------------------------------------------------
    // A note about the Id's, such as X509-FC77E2C72083DA8E0F16711753508182856, TS-FC77E2C72083DA8E0F16711753508042855, etc.
    // These Id's simply need to be unique within the XML document.  You don't need to generate new Id's every time.
    // You can use the same Id's in each XML document that is submitted. The purpose of each Id is to
    // match the XMLDsig Reference to the element in XML being referenced.
    // In other words, you could use the Id's "mickey_mouse", "donald_duck", and "goofy", and it would work perfectly OK,
    // as long as no other XML elements also use the Id's "mickey_mouse", "donald_duck", or "goofy"
    // ---------------------------------------------------------------------------------------------------------------

    const bd_cert = try chilkat.BinData.init();
    defer bd_cert.deinit();
    cert.exportCertDerBd(bd_cert) catch {};

    xml_to_sign.updateChildContent("soapenv:Header|wsse:Security|wsse:BinarySecurityToken", try bd_cert.getEncoded(alloc, "base64"));
    xml_to_sign.updateAttrAt("soapenv:Header|wsse:Security|wsu:Timestamp", true, "wsu:Id", "TS-FC77E2C72083DA8E0F16711753508042855") catch {};

    const dt = try chilkat.DateTime.init();
    defer dt.deinit();
    dt.setFromCurrentSystemTime() catch {};
    xml_to_sign.updateChildContent("soapenv:Header|wsse:Security|wsu:Timestamp|wsu:Created", try dt.getAsTimestamp(alloc, false));
    dt.addSeconds(3600) catch {};
    xml_to_sign.updateChildContent("soapenv:Header|wsse:Security|wsu:Timestamp|wsu:Expires", try dt.getAsTimestamp(alloc, false));
    dt.addSeconds(-3600) catch {};

    xml_to_sign.updateAttrAt("soapenv:Body", true, "wsu:Id", "id-FC77E2C72083DA8E0F16711753508182859") catch {};
    xml_to_sign.updateAttrAt("soapenv:Body", true, "xmlns:wsu", "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd") catch {};
    xml_to_sign.updateChildContent("soapenv:Body|urn:CheckAccessControlRequest|urn1:Message", "Hello World");

    // Create a timestamp with the current date/time in the following format: 2014-12-30T15:29:03.157+01:00

    xml_to_sign.updateChildContent("soapenv:Body|urn:CheckAccessControlRequest|urn1:Timestamp", try dt.getAsTimestamp(alloc, true));

    const gen = try chilkat.XmlDSigGen.init();
    defer gen.deinit();

    gen.setSigLocation("soapenv:Envelope|soapenv:Header|wsse:Security|wsse:BinarySecurityToken");
    gen.setSigLocationMod(1);
    gen.setSigId("SIG-FC77E2C72083DA8E0F16711753508252860");
    gen.setSigNamespacePrefix("ds");
    gen.setSigNamespaceUri("http://www.w3.org/2000/09/xmldsig#");
    gen.setSignedInfoPrefixList("soapenv urn urn1");
    gen.setIncNamespacePrefix("ec");
    gen.setIncNamespaceUri("http://www.w3.org/2001/10/xml-exc-c14n#");
    gen.setSignedInfoCanonAlg("EXCL_C14N");
    gen.setSignedInfoDigestMethod("sha256");

    // Set the KeyInfoId before adding references..
    gen.setKeyInfoId("KI-FC77E2C72083DA8E0F16711753508182857");

    // -------- Reference 1 --------
    gen.addSameDocRef("TS-FC77E2C72083DA8E0F16711753508042855", "sha256", "EXCL_C14N", "wsse soapenv urn urn1", "") catch {};

    // -------- Reference 2 --------
    gen.addSameDocRef("id-FC77E2C72083DA8E0F16711753508182859", "sha256", "EXCL_C14N", "urn urn1", "") catch {};

    // -------- Reference 3 --------
    gen.addSameDocRef("X509-FC77E2C72083DA8E0F16711753508182856", "sha256", "EXCL_C14N", "_EMPTY_", "") catch {};

    gen.setX509Cert(cert, true) catch {};

    gen.setKeyInfoType("Custom");

    // Create the custom KeyInfo XML..
    const xml_custom_key_info = try chilkat.Xml.init();
    defer xml_custom_key_info.deinit();
    xml_custom_key_info.setTag("wsse:SecurityTokenReference");
    xml_custom_key_info.addAttribute("wsu:Id", "STR-FC77E2C72083DA8E0F16711753508182858") catch {};
    xml_custom_key_info.updateAttrAt("wsse:Reference", true, "URI", "#X509-FC77E2C72083DA8E0F16711753508182856") catch {};
    xml_custom_key_info.updateAttrAt("wsse:Reference", true, "ValueType", "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-x509-token-profile-1.0#X509v3") catch {};

    xml_custom_key_info.setEmitXmlDecl(false);
    gen.setCustomKeyInfoXml(try xml_custom_key_info.getXml(alloc));

    // Load XML to be signed...
    const sb_xml = try chilkat.StringBuilder.init();
    defer sb_xml.deinit();
    xml_to_sign.getXmlSb(sb_xml) catch {};

    gen.setBehaviors("IndentedSignature");

    // Sign the XML...
    gen.createXmlDSigSb(sb_xml) catch {
        std.debug.print("{s}\n", .{try gen.getLastErrorText(alloc)});
        return;
    };

    // -----------------------------------------------
    // Send the signed XML...
    const http = try chilkat.Http.init();
    defer http.deinit();

    http.setSslClientCert(cert) catch {
        std.debug.print("{s}\n", .{try http.getLastErrorText(alloc)});
        return;
    };

    http.setRequestHeader("Content-Type", "text/xml");

    // Change to services.ehealth.fgov.be for the production environment.
    const resp = try chilkat.HttpResponse.init();
    defer resp.deinit();
    http.httpSb("POST", "https://services-acpt.ehealth.fgov.be/PlatformIntegrationConsumerTest/v1", sb_xml, "utf-8", "application/xml", resp) catch {
        std.debug.print("{s}\n", .{try http.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("{s}\n", .{try resp.getBodyStr(alloc)});
    std.debug.print("response status code = {d}\n", .{resp.getStatusCode()});

    // A successful response is a 200 status code, with this sample response:

    // <soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/">
    //    <soapenv:Header xmlns:v1="urn:be:fgov:ehealth:platformintegrationconsumertest:v1" xmlns:v11="urn:be:fgov:ehealth:platformintegrationconsumertest:types:v1"/>
    //    <soapenv:Body xmlns:ic="urn:be:fgov:ehealth:platformintegrationconsumertest:v1" xmlns:type="urn:be:fgov:ehealth:platformintegrationconsumertest:types:v1">
    //       <ic:CheckAccessControlResponse>
    //          <type:Message>Hello World</type:Message>
    //          <type:Timestamp>2023-09-28T22:17:26.643+02:00</type:Timestamp>
    //          <type:AuthenticatedConsumer>CN="SSIN=aaaaaa", OU=eHealth-platform Belgium, OU=bbbb, OU="SSIN=aaaaaaa", O=Federal Government, C=BE</type:AuthenticatedConsumer>
    //       </ic:CheckAccessControlResponse>
    //    </soapenv:Body>
    // </soapenv:Envelope>
}