Sample code for 30+ languages & platforms
Zig

Add EncapsulatedTimestamp to Already-Signed XML

See more XML Digital Signatures Examples

Demonstrates how to add an EncapsulatedTimestamp to an existing XML signature.

Note: This example requires Chilkat v9.5.0.90 or greater.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // Note: We cannot load the already-signed XML into a Chilkat XML object because it would re-format the XML when re-emitted.
    // (i.e. indentation and whitespace could change, and it would invalidate the existing signature.)
    // We must use a StringBuilder.
    const sb_xml = try chilkat.StringBuilder.init();
    defer sb_xml.deinit();
    sb_xml.loadFile("qa_data/xml_dsig_valid_samples/encapsulatedTimestamp_not_yet_added.xml", "utf-8") catch {
        std.debug.print("Failed to load the XML file.\n", .{});
        return;
    };

    const dsig = try chilkat.XmlDSig.init();
    defer dsig.deinit();
    dsig.loadSignatureSb(sb_xml) catch {
        std.debug.print("{s}\n", .{try dsig.getLastErrorText(alloc)});
        return;
    };

    if (dsig.hasEncapsulatedTimeStamp()) {
        std.debug.print("This signed XML already has an EncapsulatedTimeStamp\n", .{});
        return;
    }

    // Specify the timestamping authority URL
    const json = try chilkat.JsonObject.init();
    defer json.deinit();
    json.updateString("timestampToken.tsaUrl", "http://timestamp.digicert.com") catch {};
    json.updateBool("timestampToken.requestTsaCert", true) catch {};

    // Call AddEncapsulatedTimeStamp to add the EncapsulatedTimeStamp to the signature.
    // Note: If the signed XML contains multiple signatures, the signature modified is the one
    // indicated by the dsig.Selector property.
    const sb_out = try chilkat.StringBuilder.init();
    defer sb_out.deinit();
    dsig.addEncapsulatedTimeStamp(json, sb_out) catch {
        std.debug.print("{s}\n", .{try dsig.getLastErrorText(alloc)});
        return;
    };

    sb_out.writeFile("qa_output/addedEncapsulatedTimeStamp.xml", "utf-8", false) catch {};

    // The EncapsulatedTimeStamp can be validated when validating the signature by adding the VerifyEncapsulatedTimeStamp
    // keyword to UncommonOptions.  See here:

    // ----------------------------------------
    // Verify the signatures we just produced...
    const verifier = try chilkat.XmlDSig.init();
    defer verifier.deinit();
    verifier.loadSignatureSb(sb_out) catch {
        std.debug.print("{s}\n", .{try verifier.getLastErrorText(alloc)});
        return;
    };

    // Add "VerifyEncapsulatedTimeStamp" to the UncommonOptions to also verify any EncapsulatedTimeStamps
    verifier.setUncommonOptions("VerifyEncapsulatedTimeStamp");

    const num_sigs = verifier.getNumSignatures();
    var verify_idx: i32 = 0;
    while (verify_idx < num_sigs) {
        verifier.setSelector(verify_idx);
        verifier.verifySignature(true) catch {
            std.debug.print("{s}\n", .{try verifier.getLastErrorText(alloc)});
            return;
        };

        verify_idx = verify_idx + 1;
    }

    std.debug.print("All signatures were successfully verified.\n", .{});
}