Jwe CkPython Reference Documentation
CkJwe
Current Version: 11.1.0
An API for JSON Web Encryption (JWE). Provides the ability to create (encrypt) and decrypt JWE's.
Supported Algorithms:
- RSAES OAEP 256 (using SHA-256 and MGF1 with SHA-256) encryption with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
- RSAES OAEP (using SHA-1 and MGF1 with SHA-1) encryption with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
- RSAES-PKCS1-V1_5 encryption with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
- Direct symmetric key encryption with pre-shared key A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM and A256GCM
- A128KW, A192KW, A256KW encryption with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
- A128GCMKW, A192GCMKW, A256GCMKW encryption with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
- PBES2-HS256+A128KW, PBES2-HS384+A192KW, PBES2-HS512+A256KW with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
Object Creation
obj = chilkat.CkJwe()
Properties
DebugLogFilePath
# ckStr is a CkString
jwe.get_DebugLogFilePath(ckStr);
strVal = jwe.debugLogFilePath();
jwe.put_DebugLogFilePath(strVal);
If set to a file path, this property logs the LastErrorText of each Chilkat method or property call to the specified file. This logging helps identify the context and history of Chilkat calls leading up to any crash or hang, aiding in debugging.
Enabling the VerboseLogging property provides more detailed information. This property is mainly used for debugging rare instances where a Chilkat method call causes a hang or crash, which should generally not happen.
Possible causes of hangs include:
- A timeout property set to 0, indicating an infinite timeout.
- A hang occurring within an event callback in the application code.
- An internal bug in the Chilkat code causing the hang.
LastErrorHtml
# ckStr is a CkString
jwe.get_LastErrorHtml(ckStr);
strVal = jwe.lastErrorHtml();
Provides HTML-formatted information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.
topLastErrorText
# ckStr is a CkString
jwe.get_LastErrorText(ckStr);
strVal = jwe.lastErrorText();
Provides plain text information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.
LastErrorXml
# ckStr is a CkString
jwe.get_LastErrorXml(ckStr);
strVal = jwe.lastErrorXml();
Provides XML-formatted information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.
topLastMethodSuccess
boolVal = jwe.get_LastMethodSuccess();
jwe.put_LastMethodSuccess(boolVal);
Indicates the success or failure of the most recent method call: True means success, False means failure. This property remains unchanged by property setters or getters.  This method is present to address challenges in checking for null or Nothing returns in certain programming languages.
NumRecipients
intVal = jwe.get_NumRecipients();
The number of recipients for this JWE.
topPreferCompact
boolVal = jwe.get_PreferCompact();
jwe.put_PreferCompact(boolVal);
Controls whether  the JWE Compact Serialization or JWE JSON Serialization is preferred when creating JWEs.  The default value is True, which is to use compact serialization when possible.  If multiple recipients exist, or if any unprotected headers exist, then JWE JSON Serialization is used regardless of this property setting.
PreferFlattened
boolVal = jwe.get_PreferFlattened();
jwe.put_PreferFlattened(boolVal);
Controls whether  the flattened serialization is preferred when JWE JSON Serialization is used.  The default value is True, which is to use the flattened serialization when possible.  If multiple recipients exist, then the general (non-flattened) JWE JSON Serialization is used regardless of this property setting.
UncommonOptions
# ckStr is a CkString
jwe.get_UncommonOptions(ckStr);
strVal = jwe.uncommonOptions();
jwe.put_UncommonOptions(strVal);
This is a catch-all property to be used for uncommon needs. This property defaults to the empty string and should typically remain empty.
topVerboseLogging
boolVal = jwe.get_VerboseLogging();
jwe.put_VerboseLogging(boolVal);
If set to True, then the contents of LastErrorText (or LastErrorXml, or LastErrorHtml) may contain more verbose information. The default value is False.  Verbose logging should only be used for debugging.  The potentially large quantity of logged information may adversely affect peformance.
Version
Methods
Decrypt
# charset is a string
# outStr is a CkString (output)
status = jwe.Decrypt(index, charset, outStr);
retStr = jwe.decrypt(index, charset);
Decrypts a JWE and returns the original (decrypted) string content.  The byte representation of the decrypted bytes is indicated by charset (such as utf-8).  (The charset tells Chilkat how to intepret the decrypted bytes as characters.)
The index specifies which recipient key is used for decryption. (Most JWEs have only a single recipent, and thus the index is typically 0.)
Supported Algorithms:
- RSAES OAEP 256 (using SHA-256 and MGF1 with SHA-256) encryption with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
- RSAES OAEP (using SHA-1 and MGF1 with SHA-1) encryption with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
- RSAES-PKCS1-V1_5 encryption with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
- Direct symmetric key encryption with pre-shared key A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM and A256GCM
- A128KW, A192KW, A256KW encryption with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
- A128GCMKW, A192GCMKW, A256GCMKW encryption with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
- PBES2-HS256+A128KW, PBES2-HS384+A192KW, PBES2-HS512+A256KW with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
Returns True for success, False for failure.
DecryptBd
Decrypts the loaded JWE and appends the decrypted bytes to the contents of bd. The index specifies which recipient key is used for decryption. (Most JWEs have only a single recipent, and thus the index is typically 0.)
Returns True for success, False for failure.
DecryptSb
# charset is a string
# contentSb is a CkStringBuilder
status = jwe.DecryptSb(index, charset, contentSb);
Decrypts the loaded JWE and appends the decrypted content to contentSb.  The byte representation of the decrypted bytes is indicated by charset (such as utf-8).  (This tells Chilkat how to interpret the bytes as characters.)
The index specifies which recipient key is used for decryption. (Most JWEs have only a single recipent, and thus the index is typically 0.)
Returns True for success, False for failure.
Encrypt
# charset is a string
# outStr is a CkString (output)
status = jwe.Encrypt(content, charset, outStr);
retStr = jwe.encrypt(content, charset);
Encrypts string content to produce a JWE.  The byte representation of the content is indicated by charset (such as utf-8).
Supported Algorithms:
- RSAES OAEP 256 (using SHA-256 and MGF1 with SHA-256) encryption with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
- RSAES OAEP (using SHA-1 and MGF1 with SHA-1) encryption with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
- RSAES-PKCS1-V1_5 encryption with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
- Direct symmetric key encryption with pre-shared key A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM and A256GCM
- A128KW, A192KW, A256KW encryption with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
- A128GCMKW, A192GCMKW, A256GCMKW encryption with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
- PBES2-HS256+A128KW, PBES2-HS384+A192KW, PBES2-HS512+A256KW with A128CBC-HS256, A192CBC-HS384, A256CBC-HS512, A128GCM, A192GCM, A256GCM
Returns True for success, False for failure.
EncryptBd
Encrypts the contents of contentBd to produce a JWE that is appended to the contents of jweSb. (This method provides the means to produce a JWE from binary content.)
Returns True for success, False for failure.
EncryptSb
# charset is a string
# jweSb is a CkStringBuilder
status = jwe.EncryptSb(contentSb, charset, jweSb);
Encrypts the contents of contentSb to produce a JWE that is appended to the contents of jweSb.  The byte representation of the string to be encrypted is indicated by charset (such as utf-8).
Returns True for success, False for failure.
FindRecipient
# paramValue is a string
# caseSensitive is a boolean
retInt = jwe.FindRecipient(paramName, paramValue, caseSensitive);
Finds the index of the recipient with a header parameter (paramName) equal to a specified value (paramValue).   Returns -1 if no recipient contains a header with the given name/value.   If caseSensitive is True, then the header param name/value comparisons are case sensitive.  Otherwise it is case insensitive.
The procedure for decrypting a JWE with multiple recipients is the following:
- Load the JWE via one of the Load* methods.
- Find the recipient index by some identifying header paramter.  The typical case is via the kidheader parameter. (kidis an arbitrary key ID applications can assign to identify keys.)
- Set the key for decryption at the found index by calling SetPrivateKey, SetWrappingKey, or SetPassword, depending on the type of key wrapping that is employed.
- Call Decrypt, DecryptSb, or DecryptBd to decrypt for the recipient (and key) at the given index.
GetHeader
Returns the JSON header from the JWE. The JSON header is loaded into json.
Returns True for success, False for failure.
topGetProtectedHeader
Returns the shared protected JSON header from the JWE. The shared protected header is loaded into json.
Returns True for success, False for failure.
topLoadJwe
status = jwe.LoadJwe(jwe);
Loads the contents of a JWE.
Returns True for success, False for failure.
LoadJweSb
Loads the contents of a JWE from a StringBuilder object.
Returns True for success, False for failure.
SetAad
# charset is a string
status = jwe.SetAad(aad, charset);
Sets the optional Additional Authenticated Data.  This is only used for non-compact serializations.  The charset specifies the character encoding (such as utf-8) to be used for the byte representation for the additional authenticated data.
Returns True for success, False for failure.
topSetAadBd
Sets the optional Additional Authenticated Data. This is only used for non-compact serializations. This method provides a way for binary (non-text) additional authenticated data to be used.
Returns True for success, False for failure.
topSetPassword
# password is a string
status = jwe.SetPassword(index, password);
Sets the PBES2 password for key encryption or decryption.  This is for the case where the content encryption key (CEK) is encrypted using PBES2.  An PBES2 password should be used  in the cases where the alg header parameter value is equal to one of the following:
PBES2-HS256+A128KW PBES2-HS384+A192KW PBES2-HS512+A256KWThe index is the index of the recipient, where the 1st recipient is at index 0. (The typical use case for JWEs is for a single recipient.)
Returns True for success, False for failure.
topSetPrivateKey
Sets a private key for RSA key unwrapping/decryption.  This is for the case where the content encryption key (CEK) is encrypted using RSA.  An RSA private key should be used for decrypting in the cases where the alg header parameter value is equal to one of the following:
RSA1_5 RSA-OAEP RSA-OAEP-256 RSA-OAEP-384 (added in Chilkat v9.5.0.71) RSA-OAEP-512 (added in Chilkat v9.5.0.71)The index is the index of the recipient, where the 1st recipient is at index 0. (The typical use case for JWEs is for a single recipient.)
Returns True for success, False for failure.
SetProtectedHeader
Sets the JWE Protected Header.
Returns True for success, False for failure.
SetPublicKey
Sets a public key for RSA key wrapping encryption.  This is for the case where the content encryption key (CEK) is encrypted using RSA.  An RSA public key should be used when encrypting for the cases where the alg header parameter value is equal to one of the following:
RSA1_5 RSA-OAEP RSA-OAEP-256The index is the index of the recipient, where the 1st recipient is at index 0. (The typical use case for JWEs is for a single recipient.)
Returns True for success, False for failure.
SetRecipientHeader
Sets a per-recipient unprotected header. This method would only be called if the JWE is for multiple recipients. The 1st recipient is at index 0.
Returns True for success, False for failure.
topSetUnprotectedHeader
SetWrappingKey
# encodedKey is a string
# encoding is a string
status = jwe.SetWrappingKey(index, encodedKey, encoding);
Sets the AES wrapping key for encryption or decryption.  This is for the case where the content encryption key (CEK) is encrypted using AES Key Wrap or AES GCM.  An AES key should be used  in the cases where the alg header parameter value is equal to one of the following:
A128KW A192KW A256KW A128GCMKW A192GCMKW A256GCMKW dirThe index is the index of the recipient, where the 1st recipient is at index 0. (The typical use case for JWEs is for a single recipient.)
Note: This method also sets the shared direct symmetric key for the case when the alg is equal to dir.   In this case, the key specified is not actualy a key encryption key, but is the direct content encryption key.
The encoding indicates the representation, such as base64, hex, base64url, etc. of the encodedKey.
Returns True for success, False for failure.