Sample code for 30+ languages & platforms
Zig

SOAP WS-Security UsernameToken

See more XML Examples

Demonstrates how to add a UsernameToken with the WSS SOAP Message Security header.

Note: This example requires Chilkat v9.5.0.66 or later.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // An HTTP SOAP request is an HTTP request where the SOAP XML composes the body.
    // This example demonstrates how to add a WS-Security header such as the following:
    //
    // <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="SecurityToken-6138db82-5a4c-4bf7-915f-af7a10d9ae96">
    //   <wsse:Username>user</wsse:Username>
    //   <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">CBb7a2itQDgxVkqYnFtggUxtuqk=</wsse:Password>
    //   <wsse:Nonce>5ABcqPZWb6ImI2E6tob8MQ==</wsse:Nonce>
    //   <wsu:Created>2010-06-08T07:26:50Z</wsu:Created>
    // </wsse:UsernameToken>
    //

    // First build some simple SOAP XML that has some header and body.
    const xml = try chilkat.Xml.init();
    defer xml.deinit();
    xml.setTag("env:Envelope");
    xml.addAttribute("xmlns:env", "http://www.w3.org/2003/05/soap-envelope") catch {};
    xml.updateAttrAt("env:Header|n:alertcontrol", true, "xmlns:n", "http://example.org/alertcontrol") catch {};
    xml.updateChildContent("env:Header|n:alertcontrol|n:priority", "1");
    xml.updateChildContent("env:Header|n:alertcontrol|n:expires", "2001-06-22T14:00:00-05:00");
    xml.updateAttrAt("env:Body|m:alert", true, "xmlns:m", "http://example.org/alert") catch {};
    xml.updateChildContent("env:Body|m:alert|m:msg", "Pick up Mary at school at 2pm");
    std.debug.print("{s}\n", .{try xml.getXml(alloc)});
    std.debug.print("----\n", .{});

    // The following SOAP XML is built:

    //     <env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope">
    //      <env:Header>
    //       <n:alertcontrol xmlns:n="http://example.org/alertcontrol">
    //        <n:priority>1</n:priority>
    //        <n:expires>2001-06-22T14:00:00-05:00</n:expires>
    //       </n:alertcontrol>
    //      </env:Header>
    //      <env:Body>
    //       <m:alert xmlns:m="http://example.org/alert">
    //        <m:msg>Pick up Mary at school at 2pm</m:msg>
    //       </m:alert>
    //      </env:Body>
    //     </env:Envelope>
    //

    // Now build the WSSE XML housing that we'll insert into the above SOAP XML at the end.

    //     <wsse:Security>
    //       <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="WSU_ID">
    //         <wsse:Username>USERNAME</wsse:Username>
    //         <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">PASSWORD_DIGEST</wsse:Password>
    //         <wsse:Nonce>NONCE</wsse:Nonce>
    //         <wsu:Created>CREATED</wsu:Created>
    //       </wsse:UsernameToken>
    //     </wsse:Security>

    const wsse = try chilkat.Xml.init();
    defer wsse.deinit();
    wsse.setTag("wsse:Security");
    wsse.updateAttrAt("wsse:UsernameToken", true, "xmlns:wsu", "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd") catch {};
    wsse.updateAttrAt("wsse:UsernameToken", true, "wsu:Id", "WSU_ID") catch {};
    wsse.updateChildContent("wsse:UsernameToken|wsse:Username", "USERNAME");
    wsse.updateAttrAt("wsse:UsernameToken|wsse:Password", true, "Type", "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest") catch {};
    wsse.updateChildContent("wsse:UsernameToken|wsse:Password", "PASSWORD_DIGEST");
    wsse.updateChildContent("wsse:UsernameToken|wsse:Nonce", "NONCE");
    wsse.updateChildContent("wsse:UsernameToken|wsu:Created", "CREATED");
    std.debug.print("{s}\n", .{try wsse.getXml(alloc)});
    std.debug.print("----\n", .{});

    // Insert the wsse:Security XML into the existing SOAP header:
    const x_header = try xml.getChildWithTag("env:Header");
    defer x_header.deinit();
    x_header.addChildTree(wsse) catch {};

    // Now show the SOAP XML with the wsse:Security header added:
    std.debug.print("{s}\n", .{try xml.getXml(alloc)});
    std.debug.print("----\n", .{});

    // Now our XML looks like this:
    //     <env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope">
    //         <env:Header>
    //             <n:alertcontrol xmlns:n="http://example.org/alertcontrol">
    //                 <n:priority>1</n:priority>
    //                 <n:expires>2001-06-22T14:00:00-05:00</n:expires>
    //             </n:alertcontrol>
    //             <wsse:Security>
    //                 <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="WSU_ID">
    //                     <wsse:Username>USERNAME</wsse:Username>
    //                     <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">PASSWORD_DIGEST</wsse:Password>
    //                     <wsse:Nonce>NONCE</wsse:Nonce>
    //                     <wsu:Created>CREATED</wsu:Created>
    //                 </wsse:UsernameToken>
    //             </wsse:Security>
    //         </env:Header>
    //         <env:Body>
    //             <m:alert xmlns:m="http://example.org/alert">
    //                 <m:msg>Pick up Mary at school at 2pm</m:msg>
    //             </m:alert>
    //         </env:Body>
    //     </env:Envelope>
    //

    // -----------------------------------------------------
    // Now let's fill-in-the-blanks with actual information...
    // -----------------------------------------------------

    const wsu_id = "Example-1";
    wsse.updateAttrAt("wsse:UsernameToken", true, "wsu:Id", wsu_id) catch {};

    const password = "password";
    const username = "user";
    wsse.updateChildContent("wsse:UsernameToken|wsse:Username", username);

    // The nonce should be 16 random bytes.
    const prng = try chilkat.Prng.init();
    defer prng.deinit();
    const bd = try chilkat.BinData.init();
    defer bd.deinit();
    // Generate 16 random bytes into bd.
    // Note: The GenRandomBd method is added in Chilkat v9.5.0.66
    prng.genRandomBd(16, bd) catch {};

    const nonce = try bd.getEncoded(alloc, "base64");
    wsse.updateChildContent("wsse:UsernameToken|wsse:Nonce", nonce);

    // Get the current date/time in a string with this format: 2010-06-08T07:26:50Z
    const dt = try chilkat.DateTime.init();
    defer dt.deinit();
    dt.setFromCurrentSystemTime() catch {};
    const b_local = false;
    const created = try dt.getAsTimestamp(alloc, b_local);
    wsse.updateChildContent("wsse:UsernameToken|wsu:Created", created);

    // The password digest is calculated like this:
    // Password_Digest = Base64 ( SHA-1 ( nonce + created + password ) )
    bd.appendString(created, "utf-8") catch {};
    bd.appendString(password, "utf-8") catch {};

    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();
    crypt.setHashAlgorithm("SHA-1");
    crypt.setEncodingMode("base64");
    // Note: The HashBdENC method is added in Chilkat v9.5.0.66
    const password_digest = try crypt.hashBdENC(alloc, bd);
    wsse.updateChildContent("wsse:UsernameToken|wsse:Password", password_digest);

    // Examine the final SOAP XML with WS-Security header added.
    std.debug.print("{s}\n", .{try xml.getXml(alloc)});
}