You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Blazor Server应用中如何从Program.cs获取Azure KeyVault密钥并全局使用

从Azure KeyVault获取密钥并在Blazor组件中使用的解决方案

我已将API密钥作为机密存储在Azure KeyVault中,配置完成后调试确认在Program.cs中能成功获取到密钥值secretValue,但不知道如何在项目其他位置(如Index.razor)使用该值。原本使用用户机密时通过依赖注入Configuration获取密钥,现在尝试同样方式失败,直接在Index.razor中使用secretValue会报错:cannot use local variable declared in a top-level statement in this context。

现有代码

Program.cs

SecretClientOptions options = new SecretClientOptions()
{
    Retry =
    {
        Delay= TimeSpan.FromSeconds(2),
        MaxDelay = TimeSpan.FromSeconds(16),
        MaxRetries = 5,
        Mode = RetryMode.Exponential
     }
};
var client = new SecretClient(new Uri("https://whichepisodesapi.vault.azure.net/"), new DefaultAzureCredential(), options);

KeyVaultSecret secret = await client.GetSecretAsync("tmdbApiKey");

var secretValue = secret.Value;

Index.razor @code 部分

protected override async Task OnInitializedAsync()
{
    // 原来使用用户机密时的代码
    var tmdbApiKey = Configuration["API_key"];

    if (enteredActorName != null)
    {
        var encodedName = Uri.EscapeDataString(enteredActorName);

        var request = new HttpRequestMessage(HttpMethod.Get,
            "http://api.tmdb.org/3/search/person?api_key=" + tmdbApiKey + "&query=" + encodedName);
  
        var client = _clientFactory.CreateClient();

        HttpResponseMessage response = await client.SendAsync(request);

        if (response.IsSuccessStatusCode)
        {
           ...
        }
    }
}

解决方案

方法一:将密钥添加到Configuration中(推荐,兼容原有使用方式)

修改Program.cs,获取密钥后将其添加到Configuration集合,这样就能继续用原来的依赖注入方式获取:

SecretClientOptions options = new SecretClientOptions()
{
    Retry =
    {
        Delay= TimeSpan.FromSeconds(2),
        MaxDelay = TimeSpan.FromSeconds(16),
        MaxRetries = 5,
        Mode = RetryMode.Exponential
     }
};
var client = new SecretClient(new Uri("https://whichepisodesapi.vault.azure.net/"), new DefaultAzureCredential(), options);

KeyVaultSecret secret = await client.GetSecretAsync("tmdbApiKey");

// 将密钥添加到Configuration
builder.Configuration.AddInMemoryCollection(new Dictionary<string, string>
{
    {"API_key", secret.Value}
});

Index.razor无需大幅修改,保持原有的@inject IConfiguration Configuration即可继续使用:

@inject IConfiguration Configuration
@inject IHttpClientFactory _clientFactory

@code {
    private string enteredActorName;

    protected override async Task OnInitializedAsync()
    {
        var tmdbApiKey = Configuration["API_key"];

        if (enteredActorName != null)
        {
            var encodedName = Uri.EscapeDataString(enteredActorName);
            // 建议用字符串插值替代拼接,更简洁安全
            var request = new HttpRequestMessage(HttpMethod.Get,
                $"http://api.tmdb.org/3/search/person?api_key={tmdbApiKey}&query={encodedName}");
  
            var client = _clientFactory.CreateClient();
            HttpResponseMessage response = await client.SendAsync(request);

            if (response.IsSuccessStatusCode)
            {
                // 处理响应逻辑
            }
        }
    }
}

方法二:创建专属服务封装密钥(适合多组件复用场景)

  1. 定义服务接口与实现:
public interface IApiKeyService
{
    string TmdbApiKey { get; }
}

public class ApiKeyService : IApiKeyService
{
    public string TmdbApiKey { get; set; }
}
  1. 在Program.cs中注册服务并设置密钥:
// 注册单例服务
builder.Services.AddSingleton<IApiKeyService, ApiKeyService>();

// 获取密钥后,设置到服务实例
var apiKeyService = builder.Services.BuildServiceProvider().GetRequiredService<IApiKeyService>();
apiKeyService.TmdbApiKey = secret.Value;
  1. 在Index.razor中注入服务并使用:
@inject IApiKeyService ApiKeyService
@inject IHttpClientFactory _clientFactory

@code {
    private string enteredActorName;

    protected override async Task OnInitializedAsync()
    {
        var tmdbApiKey = ApiKeyService.TmdbApiKey;

        if (enteredActorName != null)
        {
            var encodedName = Uri.EscapeDataString(enteredActorName);
            var request = new HttpRequestMessage(HttpMethod.Get,
                $"http://api.tmdb.org/3/search/person?api_key={tmdbApiKey}&query={encodedName}");
  
            var client = _clientFactory.CreateClient();
            HttpResponseMessage response = await client.SendAsync(request);

            if (response.IsSuccessStatusCode)
            {
                // 处理响应逻辑
            }
        }
    }
}

问题原因

secretValue是Program.cs顶级语句中的局部变量,作用域仅局限于Program.cs内部,Blazor组件无法直接访问局部变量。必须通过依赖注入容器或Configuration这类全局可访问的机制,才能让其他组件获取到密钥值。

内容的提问来源于stack exchange,提问作者waterford

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 19:10:10