You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CosmosDB代码创建容器所需角色及AAD授权403错误排查

Cosmos DB创建容器时AAD授权403错误排查

问题场景

调用代码await _database.CreateContainerIfNotExistsAsync(id,partitionKeyPath);创建Cosmos DB容器时,收到如下错误:

Request blocked by Auth (myuser) : The given request [POST /dbs/UserPrivateDB/colls] cannot be authorized by AAD token in data plane.

已为本人及应用配置Cosmos DB Built-in Data Contributor、Cosmos DB Built-in Data Reader和Cosmos DB Operator角色,参考相关问题尝试后仍无法解决。

完整错误日志

warn: Microsoft.AspNetCore.Components.Server.Circuits.RemoteRenderer[100]
      Unhandled exception rendering component: Response status code does not indicate success: Forbidden (403); Substatus: 5300; ActivityId: [REDACTED]; 
      Reason: {"code":"Forbidden","message":"Request blocked by Auth: The given request [POST /dbs/<DATABASE>/colls] cannot be authorized by AAD token in data plane. Learn more: https://aka.ms/cosmos-native-rbac."}

RequestUri: https://<COSMOS_ACCOUNT>.documents.azure.com/dbs/<DATABASE>/colls
RequestMethod: POST
Header: Authorization Length: [REDACTED]
Header: User-Agent Length: [REDACTED]
Header: x-ms-activity-id Length: [REDACTED]
...
Microsoft.Azure.Cosmos.CosmosException: Response status code does not indicate success: Forbidden (403); Substatus: 5300; 
    Reason: {"code":"Forbidden","message":"Request blocked by Auth: The given request [POST /dbs/<DATABASE>/colls] cannot be authorized by AAD token in data plane."}
    at Microsoft.Azure.Cosmos.GatewayStoreClient.ParseResponseAsync(HttpResponseMessage responseMessage, ...)
    ...

fail: Microsoft.AspNetCore.Components.Server.Circuits.CircuitHost[111]
      Unhandled exception in circuit '[REDACTED-CIRCUIT-ID]'.
      Microsoft.Azure.Cosmos.CosmosException : Response status code does not indicate success: Forbidden (403); Substatus: 5300; ActivityId: [REDACTED-ACTIVITY-ID]; 
      Reason: {"code":"Forbidden","message":"Request blocked by Auth: The given request [POST /dbs/<DATABASE>/colls] cannot be authorized by AAD token in data plane. Learn more: https://aka.ms/cosmos-native-rbac."}

RequestUri: https://<COSMOS_ACCOUNT>.documents.azure.com/dbs/<DATABASE>/colls
RequestMethod: POST
Header: Authorization Length: [REDACTED]
Header: User-Agent Length: [REDACTED]
Header: x-ms-activity-id Length: [REDACTED]
...

Microsoft.Azure.Cosmos.CosmosException: Response status code does not indicate success: Forbidden (403); Substatus: 5300; 
    Reason: {"code":"Forbidden","message":"Request blocked by Auth: The given request [POST /dbs/<DATABASE>/colls] cannot be authorized by AAD token in data plane."}
    at Microsoft.Azure.Cosmos.GatewayStoreClient.ParseResponseAsync(HttpResponseMessage responseMessage, ...)
    ...

所用代码(客户端采用DefaultAzureCredential)

public class DbQueriesHandler
{
    private readonly Database _database;
    private readonly Container _userContainer;

    public DbQueriesHandler(CosmosClient client, string databaseId, string containerId)
    {
        _database = client.GetDatabase(databaseId1);
        _userContainer = client.GetContainer(databaseId2, containerId);
    }
    public async Task CreateNewContainerAsync(string containerId, string partitionKeyPath, string[] permittedUsers)
    {
        await AddPermittedUsersAsync(containerId, permittedUsers);
        await _database.CreateContainerIfNotExistsAsync(containerId, partitionKeyPath);
    }

    private async Task AddPermittedUsersAsync(string containerId, string[] permittedUsers)
    {
        const string sqlQuery = "SELECT * FROM c WHERE ARRAY_CONTAINS(@Emails, c.Email)";

        var queryDefinition = new QueryDefinition(sqlQuery)
            .WithParameter("@Emails", permittedUsers);

        var resultSet = _userContainer.GetItemQueryIterator<Account>(queryDefinition);

        while (resultSet.HasMoreResults)
        {
            var response = await resultSet.ReadNextAsync();

            foreach (var user in response)
            {
                var accessibleDbs = user.AccessibleDbs.ToList();
                accessibleDbs.Add(containerId);
                user.AccessibleDbs = accessibleDbs.ToArray();
                await _userContainer.ReplaceItemAsync(user, user.id);
            }
        }
    }
}

咨询问题

  • 创建Cosmos DB容器所需的正确角色是什么?
  • 如何解决该AAD授权403错误?

内容的提问来源于stack exchange,提问作者Kk.cs

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 02:50:17