I am using a blazor web assembly application that is not asp net core hosted for a personal website. This website is integrated with Contentful CMS which requires an api key, preview key and space id. I am currently storing these inside my own appsettings.json in www/root and accessing them by injecting IConfiguration into my service, and then accessing the values through the GetSection method.
They take the form:
"DeliveryApiKey": "A",
"ManagementApiKey": "not used",
"PreviewApiKey": "B",
"SpaceId": "C",```
This is fine for running it locally, but after some researching online, these keys would be readable and visible to users if deployed and dlls decompiled.
What is the best way to store api keys with a blazor web assembly application? I am wondering if I should create a asp net core hosted blazor project which would give me a server and shared project, but if I were to deploy it, I am unsure if that would work with github actions and netlify if I were to solely deploy the 'server' side of my project. What is the best course of action?
*Edit, this is how I use those keys to access the contentful CDA. This is the way based off the documentation.
{
var apiKey = _configuration.GetSection("ContentfulOptions").GetSection("DeliveryApiKey").Value;
var previewKey = _configuration.GetSection("ContentfulOptions").GetSection("PreviewApiKey").Value;
var spaceid = _configuration.GetSection("ContentfulOptions").GetSection("SpaceId").Value;
var httpClient = new HttpClient();
var client = new ContentfulClient(httpClient, apiKey, previewKey, spaceid);
return client;
}