CosmosDB代码创建容器所需角色及AAD授权403错误排查
Cosmos DB创建容器时AAD授权403错误排查
问题场景
调用代码await _database.CreateContainerIfNotExistsAsync(id,partitionKeyPath);创建Cosmos DB容器时,收到如下错误:
Request blocked by Auth (myuser) : The given request [POST /dbs/UserPrivateDB/colls] cannot be authorized by AAD token in data plane.
已为本人及应用配置Cosmos DB Built-in Data Contributor、Cosmos DB Built-in Data Reader和Cosmos DB Operator角色,参考相关问题尝试后仍无法解决。
完整错误日志
warn: Microsoft.AspNetCore.Components.Server.Circuits.RemoteRenderer[100] Unhandled exception rendering component: Response status code does not indicate success: Forbidden (403); Substatus: 5300; ActivityId: [REDACTED]; Reason: {"code":"Forbidden","message":"Request blocked by Auth: The given request [POST /dbs/<DATABASE>/colls] cannot be authorized by AAD token in data plane. Learn more: https://aka.ms/cosmos-native-rbac."} RequestUri: https://<COSMOS_ACCOUNT>.documents.azure.com/dbs/<DATABASE>/colls RequestMethod: POST Header: Authorization Length: [REDACTED] Header: User-Agent Length: [REDACTED] Header: x-ms-activity-id Length: [REDACTED] ... Microsoft.Azure.Cosmos.CosmosException: Response status code does not indicate success: Forbidden (403); Substatus: 5300; Reason: {"code":"Forbidden","message":"Request blocked by Auth: The given request [POST /dbs/<DATABASE>/colls] cannot be authorized by AAD token in data plane."} at Microsoft.Azure.Cosmos.GatewayStoreClient.ParseResponseAsync(HttpResponseMessage responseMessage, ...) ... fail: Microsoft.AspNetCore.Components.Server.Circuits.CircuitHost[111] Unhandled exception in circuit '[REDACTED-CIRCUIT-ID]'. Microsoft.Azure.Cosmos.CosmosException : Response status code does not indicate success: Forbidden (403); Substatus: 5300; ActivityId: [REDACTED-ACTIVITY-ID]; Reason: {"code":"Forbidden","message":"Request blocked by Auth: The given request [POST /dbs/<DATABASE>/colls] cannot be authorized by AAD token in data plane. Learn more: https://aka.ms/cosmos-native-rbac."} RequestUri: https://<COSMOS_ACCOUNT>.documents.azure.com/dbs/<DATABASE>/colls RequestMethod: POST Header: Authorization Length: [REDACTED] Header: User-Agent Length: [REDACTED] Header: x-ms-activity-id Length: [REDACTED] ... Microsoft.Azure.Cosmos.CosmosException: Response status code does not indicate success: Forbidden (403); Substatus: 5300; Reason: {"code":"Forbidden","message":"Request blocked by Auth: The given request [POST /dbs/<DATABASE>/colls] cannot be authorized by AAD token in data plane."} at Microsoft.Azure.Cosmos.GatewayStoreClient.ParseResponseAsync(HttpResponseMessage responseMessage, ...) ...
所用代码(客户端采用DefaultAzureCredential)
public class DbQueriesHandler { private readonly Database _database; private readonly Container _userContainer; public DbQueriesHandler(CosmosClient client, string databaseId, string containerId) { _database = client.GetDatabase(databaseId1); _userContainer = client.GetContainer(databaseId2, containerId); } public async Task CreateNewContainerAsync(string containerId, string partitionKeyPath, string[] permittedUsers) { await AddPermittedUsersAsync(containerId, permittedUsers); await _database.CreateContainerIfNotExistsAsync(containerId, partitionKeyPath); } private async Task AddPermittedUsersAsync(string containerId, string[] permittedUsers) { const string sqlQuery = "SELECT * FROM c WHERE ARRAY_CONTAINS(@Emails, c.Email)"; var queryDefinition = new QueryDefinition(sqlQuery) .WithParameter("@Emails", permittedUsers); var resultSet = _userContainer.GetItemQueryIterator<Account>(queryDefinition); while (resultSet.HasMoreResults) { var response = await resultSet.ReadNextAsync(); foreach (var user in response) { var accessibleDbs = user.AccessibleDbs.ToList(); accessibleDbs.Add(containerId); user.AccessibleDbs = accessibleDbs.ToArray(); await _userContainer.ReplaceItemAsync(user, user.id); } } } }
咨询问题
- 创建Cosmos DB容器所需的正确角色是什么?
- 如何解决该AAD授权403错误?
内容的提问来源于stack exchange,提问作者Kk.cs
相关产品推荐
相关产品推荐

