【问题标题】:How to secure smtp info with Azure and Github?如何使用 Azure 和 Github 保护 smtp 信息?
【发布时间】:2017-03-08 13:09:01
【问题描述】:

我有一个小网站,它有一个联系我页面,对于这个页面我使用System.Net.Mail 并关注this tutorial。

我现在的问题是我在 Azure 上托管我的网站并使用 Github 作为源代码控制和部署。

当然,问题是我的所有代码都将在 Github 上公开,并且凭据已公开。

如何使用 Azure 保护这些信息不让公众知道? 我一直在研究“应用设置”部分,但我不能 100% 确定如何正确处理。

  <system.net>
    <mailSettings>
      <smtp from="mail@outlook.com">
        <network host="smtp-mail.outlook.com"
                 port="587"
                 userName="mail@outlook.com"
                 password="notarealpassword"
                 enableSsl="true" />
      </smtp>
    </mailSettings>
  </system.net>

【问题讨论】:

    标签: asp.net-mvc security azure github azure-web-app-service


    【解决方案1】:

    所以最简单的方法是使用应用设置(就像你说的那样)。您将创建多个应用程序设置,例如username = mail@outlook.com,这些设置将成为 VM 托管您的 WebApp 上的环境变量。您可以以任何您喜欢的方式通过变量名称获取值或那些环境变量。

    我正在这样做:

    Environment.GetEnvironmentVariable("StorageConnectionString")
    

    【讨论】:

    • 这确实是我也很有趣的想法,但这意味着我必须将设置从配置文件中取出并再次放入代码中,对吧?
    • 如果我理解正确,你可以访问web.config中的stackoverflow.com/questions/32301840/…
    【解决方案2】:

    我的解决方案基于4c74356b41 的回答。

    第 1 步:将密钥添加到您的 Web.config 文件

    将值留空。

      <appSettings>
        <add key="webpages:Version" value="3.0.0.0" />
        <add key="webpages:Enabled" value="false" />
        <add key="ClientValidationEnabled" value="true" />
        <add key="UnobtrusiveJavaScriptEnabled" value="true" />
    
        <add key="EmailAccount" value=""/>
        <add key="EmailPassword" value=""/>
      </appSettings>
    

    第 2 步:使用代码中的密钥

    使用ConfigurationManager,您可以调用AppSettings 并根据键名检索值。

           using (var smtp = new SmtpClient())
            {
                var credential = new NetworkCredential
                {
                    UserName = ConfigurationManager.AppSettings["EmailAccount"],  
                    Password = ConfigurationManager.AppSettings["EmailPassword"]  
                };
                smtp.Credentials = credential;
                smtp.Host = "smtp-mail.outlook.com";
                smtp.Port = 587;
                smtp.EnableSsl = true;
                await smtp.SendMailAsync(message);
                return RedirectToAction("Sent");
            }
    

    第 3 步:将键值添加到 Azure 上的应用设置

    在您的 Web 应用程序中,转到“设置”下的“应用程序设置”并添加您的键/值

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2012-08-17
      • 1970-01-01
      • 2022-12-20
      • 1970-01-01
      • 2019-09-07
      • 2012-09-27
      • 2017-01-31
      • 1970-01-01
      相关资源
      最近更新 更多