Sample code for 30+ languages & platforms
Zig

HMRC Validate Fraud Prevention Headers

See more HTTP Misc Examples

Demonstrates how to test (validate) HMRC fraud prevention headers.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const rest = try chilkat.Rest.init();
    defer rest.deinit();

    rest.connect("test-api.service.hmrc.gov.uk", 443, true, true) catch {
        std.debug.print("{s}\n", .{try rest.getLastErrorText(alloc)});
        return;
    };

    // Load the previously fetched access token.
    const json = try chilkat.JsonObject.init();
    defer json.deinit();
    try json.loadFile("qa_data/tokens/hmrc.json");
    const access_token = try json.stringOf(alloc, "access_token");
    std.debug.print("Using access toke: {s}\n", .{access_token});

    const sb_auth_header_value = try chilkat.StringBuilder.init();
    defer sb_auth_header_value.deinit();
    sb_auth_header_value.append("Bearer ") catch {};
    sb_auth_header_value.append(access_token) catch {};

    rest.addHeader("Accept", "application/vnd.hmrc.1.0+json") catch {};
    rest.addHeader("Authorization", try sb_auth_header_value.getAsString(alloc)) catch {};

    // Add the fraud prevention headers.
    // See https://developer.service.hmrc.gov.uk/api-documentation/docs/fraud-prevention
    rest.addHeader("gov-client-connection-method", "DESKTOP_APP_DIRECT") catch {};

    // This should be generated by an application and persistently stored on the device. The identifier should not expire.
    rest.addHeader("gov-client-device-id", "beec798b-b366-47fa-b1f8-92cede14a1ce") catch {};

    // See https://developer.service.hmrc.gov.uk/api-documentation/docs/fraud-prevention
    rest.addHeader("gov-client-user-ids", "os=user123") catch {};

    // Your local IP addresses (comma separated), such as addresses beginning with "192.168." or "172.16."
    rest.addHeader("gov-client-local-ips", "172.16.16.23") catch {};
    // You'll need to find a way to get your MAC address.  Chilkat does not yet provide this ability...
    rest.addHeader("gov-client-mac-addresses", "7C%3AD3%3A0A%3A25%3ADA%3A1C") catch {};

    rest.addHeader("gov-client-timezone", "UTC+00:00") catch {};

    // You can probably just hard-code these so they're always the same with each request.
    rest.addHeader("gov-client-window-size", "width=1256&height=800") catch {};
    rest.addHeader("gov-client-screens", "width=1920&height=1080&scaling-factor=1&colour-depth=16") catch {};
    rest.addHeader("gov-client-user-agent", "Windows/Server%202012 (Dell%20Inc./OptiPlex%20980)") catch {};
    rest.addHeader("gov-vendor-version", "My%20Desktop%20Software=1.2.3.build4286") catch {};

    const response_str = rest.fullRequestNoBody(alloc, "GET", "/test/fraud-prevention-headers/validate") catch {
        std.debug.print("{s}\n", .{try rest.getLastErrorText(alloc)});
        return;
    };

    // If the status code is 200, then the fraud prevention headers were validated.
    // The JSON response may include some warnings..
    std.debug.print("Response status code = {d}\n", .{rest.getResponseStatusCode()});
    std.debug.print("Response JSON body: \n", .{});
    std.debug.print("{s}\n", .{response_str});
}