At my company we are currently writing an application which runs on Blazor WASM client side and connects to an API Manager on Azure, albeit only after a relevant api key has been sent with the requests.
The trouble I am having is, safe storage of production secrets. Ideally, I'd like to hide both the port names for the relevant deployment slot's apis, the api key, as well as the B2C Client Id information (We use Azure B2C for client side authentication)
I understand that the API manager can be configured to utilize our B2C Access Token after login as part of the authentication process, but one still needs to safely store the api key, the port names, and the client ID. I've tried to use Azure Key Vault with Managed Identity (Even though the documentation states it is not supported in Blazor, I had to try out of desperation) and as expected I got errors in the code at runtime - "ArgsPlatformNotSupportedException". I was really hoping this would work as it would have made it A LOT easier to implement secret storage, especially as our app is deployed on Azure App Service. I also tried overwriting appsettings through the App Service App Settings menu, but that doesn't work either. I tried accessing Azure App Settings as environment variables, but that also doesn't work as I quite foolishly didn't realize that a browser application would very much be limited to env variables for that process.
So my question is, what IS the currently supported best practice method of securing secrets during production in Blazor WebAssembly? The documentation warns you that Key Vault and App Configuration aren't supported, tells you not to use appsettings.json for production secrets, but doesn't provide any useful alternatives.
Thank you for your time!