迁移至Firebase第二代函数后,Storage签名URL访问报SignatureDoesNotMatch错误
问题:Firebase第二代函数上传Storage文件后签名URL失效
代码背景
此前使用以下代码将图片上传至Firebase Storage:
const file = admin .storage() .bucket() .file("my path to save the image") const mainPromise = file .save(buffer, { resumable: false, contentType: "auto" }) .then(() => file.getSignedUrl({ action: "read", expires: "03-17-2100" })) .then(([url]) => url) const url = await Promise.resolve(mainPromise)
迁移情况
近期将包含上述代码的函数迁移至第二代函数,更新后的函数使用的服务账号拥有以下角色:
- roles/datastore.importExportAdmin
- roles/deploymentmanager.editor
- roles/iam.serviceAccountTokenCreator
当前正常功能
当前配置下,可完成以下操作:
- 通过前端调用GCP可调用函数上传图片;
- 使用上传时生成的签名URL访问图片。
出现的问题
但部分迁移后上传的图片,在上传一段时间后打开时出现如下错误:
<Error> <Code>SignatureDoesNotMatch</Code> <Message>Access denied.</Message> <Details>The request signature we calculated does not match the signature you provided. Check your Google secret key and signing method.</Details> <StringToSign>GET 4108924800 "the image path I'm trying to get..."</StringToSign> </Error>
疑问
第二代函数的服务账号是否需要特定角色,才能实现Storage文件上传及长期(如数月后)正常访问?或是我还遗漏了其他配置?
内容的提问来源于stack exchange,提问作者toom501
相关产品推荐
相关产品推荐

