You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为已发布的VS Code扩展安全存储敏感API密钥及环境变量?

为VS Code扩展安全存储私密API密钥的方案

一、VS Code扩展端的安全存储方案

发布扩展后,本地的.env和launch.json配置不再适用,推荐以下两种官方支持的安全方案:

1. 使用VS Code Secret Storage API(推荐)

这是VS Code专门为扩展提供的敏感信息存储API,密钥会基于系统安全机制加密存储(Windows Credential Manager、macOS Keychain、Linux libsecret),不会暴露在配置文件中。

示例代码:

import * as vscode from 'vscode';

export async function activate(context: vscode.ExtensionContext) {
    // 获取Secret Storage实例
    const secretStorage = context.secrets;
    
    // 读取已存储的密钥
    let apiKey = await secretStorage.get('externalApiKey');
    
    if (!apiKey) {
        // 提示用户输入密钥
        const input = await vscode.window.showInputBox({
            prompt: '请输入外部API的私密密钥',
            password: true, // 输入时隐藏内容
            ignoreFocusOut: true
        });
        
        if (input) {
            // 存储密钥
            await secretStorage.store('externalApiKey', input);
            apiKey = input;
        } else {
            vscode.window.showErrorMessage('未提供API密钥,扩展功能无法使用');
            return;
        }
    }
    
    // 使用apiKey发起授权请求
    // yourApiRequestFunction(apiKey);
}

2. 使用VS Code用户/工作区配置

通过扩展贡献配置项,让用户在VS Code设置中输入密钥,VS Code会自动加密标记为secret的配置项。

首先在package.json中声明配置:

"contributes": {
    "configuration": {
        "title": "你的扩展名称",
        "properties": {
            "yourExtensionId.externalApiKey": {
                "type": "string",
                "description": "访问外部API的私密密钥",
                "secret": true, // 标记为敏感配置,自动加密
                "default": ""
            }
        }
    }
}

然后在扩展中读取配置:

import * as vscode from 'vscode';

export function activate(context: vscode.ExtensionContext) {
    const config = vscode.workspace.getConfiguration('yourExtensionId');
    let apiKey = config.get<string>('externalApiKey');
    
    if (!apiKey) {
        vscode.window.showInputBox({
            prompt: '请输入外部API的私密密钥',
            password: true
        }).then(async input => {
            if (input) {
                // 保存到用户全局配置
                await config.update('externalApiKey', input, vscode.ConfigurationTarget.Global);
                apiKey = input;
                // yourApiRequestFunction(apiKey);
            }
        });
    } else {
        // yourApiRequestFunction(apiKey);
    }
}

二、Azure环境下的密钥托管方案

如果你的扩展依赖Azure服务,或需要云托管密钥,可采用以下方式:

1. Azure Key Vault(企业级推荐)

  • 在Azure门户创建Key Vault实例,将API密钥作为Secret存入Vault。
  • 给扩展的访问身份(如本地开发用Azure CLI身份、云部署用托管身份)分配Secret Get权限。
  • 使用Azure SDK读取密钥:
import { DefaultAzureCredential } from "@azure/identity";
import { SecretClient } from "@azure/keyvault-secrets";

// 初始化客户端
const credential = new DefaultAzureCredential();
const vaultUrl = "https://your-vault-name.vault.azure.net";
const secretClient = new SecretClient(vaultUrl, credential);

// 读取密钥
async function getApiKey() {
    const secret = await secretClient.getSecret("your-api-key-secret-name");
    return secret.value;
}

2. Azure App Service应用设置(针对后端服务)

如果扩展的后端部署在Azure App Service:

  • 登录Azure门户,进入目标App Service实例。
  • 导航至「配置」>「应用程序设置」,添加新的设置项(如EXTERNAL_API_KEY)并填入密钥。
  • 应用可通过环境变量读取:
const apiKey = process.env.EXTERNAL_API_KEY;

App Service会自动加密存储这些设置,且不会暴露在代码中。

三、关键注意事项

  • 禁止将密钥硬编码到扩展代码或编译产物中,避免被反编译泄露。
  • 桌面端扩展优先使用Secret Storage API,安全性高于配置项。
  • 云服务场景下,Azure Key Vault提供完整的权限控制、审计日志和密钥生命周期管理。

内容的提问来源于stack exchange,提问作者Che Coelho

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 08:35:40