AuthAzureSAS Lazarus Pascal Reference Documentation

AuthAzureSAS

Current Version: 11.6.0

Chilkat.AuthAzureSAS

Create Azure Shared Access Signature tokens for signed Azure Storage requests.

Chilkat.AuthAzureSAS creates Azure Shared Access Signature authentication tokens. It defines the SAS string-to-sign, supplies the Azure Storage account access key used to compute the signature, and controls which parameters are included in the generated SAS token query string. The resulting token can be used with Chilkat.Rest, Chilkat.Http, or other request-building code that needs time-limited, permission-scoped access to Azure Storage resources.

SAS token generation

Generate a signed query-string token that authorizes limited access to an Azure Storage resource.

String-to-sign control

Provide the exact Azure SAS string-to-sign required for the storage service and resource being accessed.

Account key signing

Use the Azure Storage account access key to compute the signature placed in the generated SAS token.

Token parameters

Add signed SAS parameters such as permissions, expiry, resource type, API version, protocol, or IP restrictions.

Non-token parameters

Add query parameters that should accompany the request but should not be included as part of the SAS token itself.

REST integration

Use the generated SAS query string with Azure Storage requests built using Chilkat.Rest or other Chilkat HTTP workflows.

Common pattern: Create an AuthAzureSAS object, set the Azure Storage AccessKey, provide the required StringToSign, add SAS token parameters with SetTokenParam, add any extra query parameters with SetNonTokenParam, then call GenerateToken. Use AuthAzureSAS when you need a SAS query token; use Chilkat.AuthAzureStorage when you need Shared Key authorization headers instead.

Create / Free

uses
  Chilkat.AuthAzureSAS;

var
  obj: TAuthAzureSAS;
begin
  obj := TAuthAzureSAS.Create;
  try
    if not obj.IsValid then
      raise Exception.Create('Failed to create a TAuthAzureSAS instance.');

    // ... use obj ...

  finally
    obj.Free;
  end;
end;
constructor Create;

Allocates the underlying CkAuthAzureSAS object and returns a new TAuthAzureSAS instance. Simply adding Chilkat.AuthAzureSAS to the unit's uses clause is enough to locate and bind to the Chilkat shared library (DLL / .so / .dylib) at runtime — no separate load step is required. Check obj.IsValid after calling Create; it is False if the underlying library could not be found/loaded or the object could not be allocated (for example, when unlicensed).

destructor Destroy; override;

Every TAuthAzureSAS created by calling Create should eventually be released by calling .Free (inherited from TObject). The destructor automatically disposes the underlying CkAuthAzureSAS handle. A native (unmanaged) memory leak occurs if the object is never freed.

Properties

AccessKey
property AccessKey: string read GetAccessKey write SetAccessKey;
Introduced in version 9.5.0.65

This is the signing key (access key) that must be kept private. It is a base64 string such as abdTvCZFFoWUyre6erlNN+IOb9qhXgDsyhrxmZvpmxqFDwpl9oD0X9Fy0hIQa6L5UohznRLmkCtUYySO4Y2eaw==

top
DebugLogFilePath
property DebugLogFilePath: string read GetDebugLogFilePath write SetDebugLogFilePath;

If set to a file path, this property logs the LastErrorText of each Chilkat method or property call to the specified file. This logging helps identify the context and history of Chilkat calls leading up to any crash or hang, aiding in debugging.

Enabling the VerboseLogging property provides more detailed information. This property is mainly used for debugging rare instances where a Chilkat method call causes a hang or crash, which should generally not happen.

Possible causes of hangs include:

  • A timeout property set to 0, indicating an infinite timeout.
  • A hang occurring within an event callback in the application code.
  • An internal bug in the Chilkat code causing the hang.

More Information and Examples
top
LastErrorHtml
property LastErrorHtml: string read GetLastErrorHtml;

Provides HTML-formatted information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.

top
LastErrorText
property LastErrorText: string read GetLastErrorText;

Provides plain text information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.

top
LastErrorXml
property LastErrorXml: string read GetLastErrorXml;

Provides XML-formatted information about the last called method or property. If a method call fails or behaves unexpectedly, check this property for details. Note that information is available regardless of the method call's success.

top
LastMethodSuccess
property LastMethodSuccess: Boolean read GetLastMethodSuccess write SetLastMethodSuccess;

Indicates the success or failure of the most recent method call: True means success, False means failure. This property remains unchanged by property setters or getters. This method is present to address challenges in checking for null or Nothing returns in certain programming languages. Note: This property does not apply to methods that return integer values or to boolean-returning methods where the boolean does not indicate success or failure.

top
StringToSign
property StringToSign: string read GetStringToSign write SetStringToSign;
Introduced in version 9.5.0.65

Defines the format of the string to sign.

The format is specified as a comma-separated list of names. For example:

signedpermissions,signedstart,signedexpiry,canonicalizedresource,signedidentifier,signedIP,signedProtocol,signedversion,rscc,rscd,rsce,rscl,rsct
This will result in an actual string-to-sign that is composed of the values for each name separated by newline (LF) chars. For example:
signedpermissions + <code>\n</code> +  
signedstart + <code>\n</code> +  
signedexpiry + <code>\n</code> +  
canonicalizedresource + <code>\n</code> +  
signedidentifier + <code>\n</code> +  
signedIP + <code>\n</code> +  
signedProtocol + <code>\n</code> +  
signedversion + <code>\n</code> +  
rscc + <code>\n</code> +  
rscd + <code>\n</code> +  
rsce + <code>\n</code> +  
rscl + <code>\n</code> +  
rsct

More Information and Examples
top
VerboseLogging
property VerboseLogging: Boolean read GetVerboseLogging write SetVerboseLogging;

If set to True, then the contents of LastErrorText (or LastErrorXml, or LastErrorHtml) may contain more verbose information. The default value is False. Verbose logging should only be used for debugging. The potentially large quantity of logged information may adversely affect peformance.

top
Version
property Version: string read GetVersion;

Version of the component/library, such as "10.1.0"

More Information and Examples
top

Methods

Clear
procedure Clear;
Introduced in version 9.5.0.65

Clears all params set by the methods SetNonTokenParam and SetTokenParam.

Returns True for success, False for failure.

top
GenerateToken
function GenerateToken: string;
Introduced in version 9.5.0.65

Generates and returns the SAS token based on the defined StringToSign and params.

Returns True for success, False for failure.

top
SetNonTokenParam
function SetNonTokenParam(const name: string;
    const value: string): Boolean;
Introduced in version 9.5.0.65

Adds a non-token parameter name/value. This is a value that is included in the string to sign, but is NOT included in the token query params.

Returns True for success, False for failure.

top
SetTokenParam
function SetTokenParam(const name: string;
    const authParamName: string;
    const value: string): Boolean;
Introduced in version 9.5.0.65

Adds a token parameter name/value. This is a value that is included in the string to sign, and is also included in the token query params.

Returns True for success, False for failure.

top