Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Sign Manifest File to Generate a Passbook .pkpass in Memory

Demonstrates how to create a Passbook .pkpass archive by creating a signature of a manifest file and then zipping to a .pkpass archive in memory

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // ---------------------------------------------------------------------------------------------
    // This example is the same as Sign Manifest File to Generate a Passbook .pkpass file
    // except everything happens in memory (no input files, no output files)
    // ---------------------------------------------------------------------------------------------

    // First create the manifest.json

    const manifest = try chilkat.JsonObject.init();
    defer manifest.deinit();
    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();

    const zip = try chilkat.Zip.init();
    defer zip.deinit();
    zip.newZip("notUsedAndNeverCreated.zip") catch {};

    crypt.setHashAlgorithm("sha1");
    // Return hashes as lowercase hex.
    crypt.setEncodingMode("hexlower");

    var digest_str: [:0]const u8 = "";

    const png_data = try chilkat.BinData.init();
    defer png_data.deinit();
    // Assume we load the pngData with bytes for "icon.png" from somewhere, such as a byte array in memory.
    zip.addBd("icon.png", png_data) catch {};
    digest_str = try crypt.hashBdENC(alloc, png_data);
    manifest.updateString("\"icon.png\"", digest_str) catch {};

    png_data.clear() catch {};
    // Assume we load the pngData with bytes for "icon@2x.png" from somewhere...
    zip.addBd("icon@2x.png", png_data) catch {};
    digest_str = try crypt.hashBdENC(alloc, png_data);
    manifest.updateString("\"icon@2x.png\"", digest_str) catch {};

    png_data.clear() catch {};
    // Assume we load the pngData with bytes for "logo.png" from somewhere...
    zip.addBd("logo.png", png_data) catch {};
    digest_str = try crypt.hashBdENC(alloc, png_data);
    manifest.updateString("\"logo.png\"", digest_str) catch {};

    png_data.clear() catch {};
    // Assume we load the pngData with bytes for "logo@2x.png" from somewhere...
    zip.addBd("logo@2x.png", png_data) catch {};
    digest_str = try crypt.hashBdENC(alloc, png_data);
    manifest.updateString("\"logo@2x.png\"", digest_str) catch {};

    const pass_json = "{ .... }"; // Contains the contents of pass.json
    zip.addString("pass.json", pass_json, "utf-8") catch {};
    digest_str = try crypt.hashStringENC(alloc, pass_json);
    manifest.updateString("\"pass.json\"", digest_str) catch {};

    zip.addString("manifest.json", try manifest.emit(alloc), "utf-8") catch {};

    // Make sure we have the Apple WWDR intermediate certificate available for
    // the cert chain in the signature.
    const cert_vault = try chilkat.XmlCertVault.init();
    defer cert_vault.deinit();
    const apple_wwdr_cert = try chilkat.Cert.init();
    defer apple_wwdr_cert.deinit();
    apple_wwdr_cert.loadByCommonName("Apple Worldwide Developer Relations Certification Authority") catch {
        std.debug.print("The Apple WWDR intermediate certificate is not installed.\n", .{});
        std.debug.print("It is available at https://developer.apple.com/certificationauthority/AppleWWDRCA.cer\n", .{});
        std.debug.print("You may alternatively load the .cer like this...\n", .{});
        apple_wwdr_cert.loadFromFile("qa_data/certs/AppleWWDRCA.cer") catch {
            std.debug.print("{s}\n", .{try apple_wwdr_cert.getLastErrorText(alloc)});
            return;
        };
    };

    cert_vault.addCert(apple_wwdr_cert) catch {};
    crypt.useCertVault(cert_vault) catch {};

    // Use a digital certificate and private key from a PFX
    const bd_pfx = try chilkat.BinData.init();
    defer bd_pfx.deinit();
    // Assume we loaded a PFX into bdPfx....
    const pfx_password = "test123";

    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    cert.loadPfxBd(bd_pfx, pfx_password) catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    // Provide the signing cert (with associated private key).
    crypt.setSigningCert(cert) catch {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
        return;
    };

    // Specify the signed attributes to be included.
    // (These attributes appear to not be necessary, but we're including
    // them just in case they become necessary in the future.)
    const json_signed_attrs = try chilkat.JsonObject.init();
    defer json_signed_attrs.deinit();
    json_signed_attrs.updateInt("contentType", 1) catch {};
    json_signed_attrs.updateInt("signingTime", 1) catch {};
    crypt.setSigningAttributes(try json_signed_attrs.emit(alloc));

    // Sign the manifest JSON to produce a signature
    crypt.setEncodingMode("base64");
    const sig = try crypt.signStringENC(alloc, try manifest.emit(alloc));
    const bd_sig = try chilkat.BinData.init();
    defer bd_sig.deinit();
    bd_sig.appendEncoded(sig, "base64") catch {};
    zip.addBd("signature", bd_sig) catch {};

    // ---------------------------------------------------------------------------------------------
    // Note: Chilkat also has the capability to do everything in-memory (no files would be involved).
    // If this is of interest, please send email to support@chilkatsoft.com
    // ---------------------------------------------------------------------------------------------

    // Create the .pkipass archive (which is a .zip archive containing the required files).
    // the .zip is written to bdZip
    const bd_zip = try chilkat.BinData.init();
    defer bd_zip.deinit();
    zip.writeBd(bd_zip) catch {
        std.debug.print("{s}\n", .{try zip.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("Success.\n", .{});
}