You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

迁移至Firebase第二代函数后,Storage签名URL访问报SignatureDoesNotMatch错误

问题:Firebase第二代函数上传Storage文件后签名URL失效

代码背景

此前使用以下代码将图片上传至Firebase Storage:

const file = admin
    .storage()
    .bucket()
    .file("my path to save the image")
const mainPromise = file
    .save(buffer, { resumable: false, contentType: "auto" })
    .then(() => file.getSignedUrl({ action: "read", expires: "03-17-2100" }))
    .then(([url]) => url)

const url = await Promise.resolve(mainPromise) 

迁移情况

近期将包含上述代码的函数迁移至第二代函数,更新后的函数使用的服务账号拥有以下角色:

  • roles/datastore.importExportAdmin
  • roles/deploymentmanager.editor
  • roles/iam.serviceAccountTokenCreator

当前正常功能

当前配置下,可完成以下操作:

  • 通过前端调用GCP可调用函数上传图片;
  • 使用上传时生成的签名URL访问图片。

出现的问题

但部分迁移后上传的图片,在上传一段时间后打开时出现如下错误:

<Error>
    <Code>SignatureDoesNotMatch</Code>
    <Message>Access denied.</Message>
    <Details>The request signature we calculated does not match the signature you provided. Check your Google secret key and signing method.</Details>
    <StringToSign>GET 4108924800 "the image path I'm trying to get..."</StringToSign>
</Error>

疑问

第二代函数的服务账号是否需要特定角色,才能实现Storage文件上传及长期(如数月后)正常访问?或是我还遗漏了其他配置?

内容的提问来源于stack exchange,提问作者toom501

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 16:20:01