Zig
Zig
JWE using AES Key Wrap and AES_128_CBC_HMAC_SHA_256
See more JSON Web Encryption (JWE) Examples
This example duplicates the example A.3 in RFC 7516 for JSON Web Encryption (JWE).Note: This example requires Chilkat v9.5.0.66 or greater.
Chilkat Zig Downloads
const std = @import("std");
const chilkat = @import("chilkat");
pub fn main(init: std.process.Init) !void {
const alloc = init.arena.allocator();
// This requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// Note: This example requires Chilkat v9.5.0.66 or greater.
const plaintext = "Live long and prosper.";
const jwe = try chilkat.Jwe.init();
defer jwe.deinit();
// First build the JWE Protected Header: {"alg":"A128KW","enc":"A128CBC-HS256"}
const jwe_prot_hdr = try chilkat.JsonObject.init();
defer jwe_prot_hdr.deinit();
jwe_prot_hdr.appendString("alg", "A128KW") catch {};
jwe_prot_hdr.appendString("enc", "A128CBC-HS256") catch {};
jwe.setProtectedHeader(jwe_prot_hdr) catch {};
std.debug.print("JWE Protected Header: {s}\n", .{try jwe_prot_hdr.emit(alloc)});
std.debug.print("--\n", .{});
// The example A.3 in RFC 7516 uses the following 128-bit AES key,
// specified in JWK (JSON Web Key) format:
// {"kty":"oct",
// "k":"GawgguFyGrWKav7AX4VKUg"
// }
// This is just a way of saying: The key type ("kty") is
// a bunch of octets ("k") in base64url encoding.
// We can simply set the AES wrapping key like this:
const aes_wrapping_key = "GawgguFyGrWKav7AX4VKUg";
jwe.setWrappingKey(0, aes_wrapping_key, "base64url") catch {};
// Encrypt and return the JWE:
const str_jwe = jwe.encrypt(alloc, plaintext, "utf-8") catch {
std.debug.print("{s}\n", .{try jwe.getLastErrorText(alloc)});
return;
};
// Show the JWE we just created:
std.debug.print("{s}\n", .{str_jwe});
// Decrypt the JWE that was just produced.
// 1) Load the JWE.
// 2) Set the AES wrapping key.
// 3) Decrypt.
const jwe2 = try chilkat.Jwe.init();
defer jwe2.deinit();
jwe2.loadJwe(str_jwe) catch {
std.debug.print("{s}\n", .{try jwe2.getLastErrorText(alloc)});
return;
};
// Set the AES wrap key.
jwe2.setWrappingKey(0, aes_wrapping_key, "base64url") catch {};
// Decrypt.
var original_plaintext: [:0]const u8 = jwe2.decrypt(alloc, 0, "utf-8") catch {
std.debug.print("{s}\n", .{try jwe2.getLastErrorText(alloc)});
return;
};
std.debug.print("original text: \n", .{});
std.debug.print("{s}\n", .{original_plaintext});
// ---------------------------------------------------------------------------------
// It should also be possible to decrypt the JWE as shown in RFC 7516, Appendix A.3.7
// because it was produced using the same AES Wrap key.
const sb_jwe = try chilkat.StringBuilder.init();
defer sb_jwe.deinit();
sb_jwe.append("eyJhbGciOiJBMTI4S1ciLCJlbmMiOiJBMTI4Q0JDLUhTMjU2In0.") catch {};
sb_jwe.append("6KB707dM9YTIgHtLvtgWQ8mKwboJW3of9locizkDTHzBC2IlrT1oOQ.") catch {};
sb_jwe.append("AxY8DCtDaGlsbGljb3RoZQ.") catch {};
sb_jwe.append("KDlTtXchhZTGufMYmOYGS4HffxPSUrfmqCHXaI9wOGY.") catch {};
sb_jwe.append("U0m_YmjN04DJvceFICbCVQ") catch {};
jwe2.loadJweSb(sb_jwe) catch {
std.debug.print("{s}\n", .{try jwe2.getLastErrorText(alloc)});
return;
};
jwe2.setWrappingKey(0, aes_wrapping_key, "base64url") catch {};
// Decrypt.
original_plaintext = jwe2.decrypt(alloc, 0, "utf-8") catch {
std.debug.print("{s}\n", .{try jwe2.getLastErrorText(alloc)});
return;
};
std.debug.print("{s}\n", .{original_plaintext});
}