Sample code for 30+ languages & platforms
Zig

Verify XML Signature with External URL References

See more XML Digital Signatures Examples

Demonstrates how to verify an XML digital signature that includes references to URLs where the data to be digested is on a web server.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // The signed XML we wish to verify contains external references such as this:

    //     <ds:Reference Id="xmldsig-e7ae7ce2-9133-4d56-bd97-0a6aef738cc2-ref0" URI="https://www.chilkatsoft.com/images/starfish.jpg">
    //       <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
    //       <ds:DigestValue>AOU810yJV5Np/DnO29qpObqiTSTTCDvxGsX5ayiTYXI=</ds:DigestValue>
    //     </ds:Reference>
    //     <ds:Reference Id="xmldsig-e7ae7ce2-9133-4d56-bd97-0a6aef738cc2-ref1" URI="https://www.chilkatsoft.com/hamlet.xml">
    //       <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
    //       <ds:DigestValue>4sRRyWOzC7EOic4fQ9+Op1pa10DbgoBGjBvkq09LZmE=</ds:DigestValue>
    //     </ds:Reference>

    const verifier = try chilkat.XmlDSig.init();
    defer verifier.deinit();
    const http = try chilkat.Http.init();
    defer http.deinit();

    // First load the signed XML
    const sb_signed_xml = try chilkat.StringBuilder.init();
    defer sb_signed_xml.deinit();
    sb_signed_xml.loadFile("qa_data/xml_dsig_verify/signedWithExternalUrlRefs.xml", "utf-8") catch {
        std.debug.print("Failed to load signed XML.\n", .{});
        return;
    };

    verifier.loadSignatureSb(sb_signed_xml) catch {
        std.debug.print("{s}\n", .{try verifier.getLastErrorText(alloc)});
        return;
    };

    // Iterate over each reference.  If it is an external URL reference, download the data and provide it to the verifier.
    const sb_ref_uri = try chilkat.StringBuilder.init();
    defer sb_ref_uri.deinit();
    const bd = try chilkat.BinData.init();
    defer bd.deinit();
    const num_refs = verifier.getNumReferences();
    var i: i32 = 0;
    while (i < num_refs) {
        if (verifier.isReferenceExternal(i)) {
            sb_ref_uri.clear();
            sb_ref_uri.append(try verifier.referenceUri(alloc, i)) catch {};
            if (sb_ref_uri.startsWith("https://", false)) {
                std.debug.print("External URL Reference: {s}\n", .{try sb_ref_uri.getAsString(alloc)});

                // Download the data at the URL and provide to the verifier.
                http.downloadBd(try sb_ref_uri.getAsString(alloc), bd) catch {
                    std.debug.print("{s}\n", .{try http.getLastErrorText(alloc)});
                    return;
                };

                verifier.setRefDataBd(i, bd) catch {
                    std.debug.print("{s}\n", .{try verifier.getLastErrorText(alloc)});
                    return;
                };
            }
        }

        i = i + 1;
    }

    // Now that we have the external data, verify the signature..
    const b_verified = if (verifier.verifySignature(true)) true else |_| false;
    if (!b_verified) {
        std.debug.print("{s}\n", .{try verifier.getLastErrorText(alloc)});
    }

    std.debug.print("Signature verified = {}\n", .{b_verified});
}