You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

API Management策略表达式语法错误,保存失败求助

问题排查与修正

错误原因分析

当前策略存在两个问题,其中触发语法错误的核心原因是:

  • <set-body>节点的<value>中直接使用了{},API Management(APIM)策略引擎会将{}识别为表达式起始标记,但此处无对应@前缀包裹合法表达式,因此触发括号格式错误提示。

此外还存在逻辑错误:

  • Authorization头赋值中重复添加Bearer 前缀,原请求的Authorization头已包含Bearer 前缀,拼接后会变成Bearer Bearer <token>,导致目标API认证失败。

修正后的策略代码

<policies>
    <inbound>
        <validate-jwt header-name="Authorization" 
                      failed-validation-httpcode="401" 
                      failed-validation-error-message="Unauthorized. Access token is missing or invalid.">
            <openid-config url="https://uatidpbsp.b2clogin.com/uatidpbsp.onmicrosoft.com/B2C_1A_LOGIN_OOBB/v2.0/.well-known/openid-configuration" />
            <audiences>
                <audience>01c396bf-e852-b396-d0a7e4d0d373</audience>
                <audience>c2ef0c9f-98f1-920e-44fb99c98026</audience>
            </audiences>
            <issuers>
                <issuer>https://uatidpbsp.b2clogin.com/a359g4c43-4228-563k5-89b6/v2.0/</issuer>
            </issuers>
        </validate-jwt>

        <!-- Send the request to the external endpoint with the token -->
        <send-request mode="new">
            <set-url>https://obw.stdn.com.pe/api/mf/v3/ami/authorize</set-url>
            <set-method>POST</set-method>
            
            <set-header name="Authorization" exists-action="override">
                <value>@(context.Request.Headers.GetValueOrDefault("Authorization", ""))</value>
            </set-header>
            
            <set-header name="Ocp-Apim-Subscription-Key" exists-action="override">
                <value>e75ee8762a842htf96e36ba5f9z8c275</value>
            </set-header>
            
            <set-body>
                <value>@("{}")</value>
            </set-body>
        </send-request>

        <base />
    </inbound>
    <backend>
        <base />
    </backend>
    <outbound>
        <base />
    </outbound>
    <on-error>
        <base />
    </on-error>
</policies>

修改说明

  1. 修复语法错误:将<set-body>的<value>内容改为@("{}"),用APIM表达式包裹空JSON对象,避免引擎误解析大括号。也可选择用CDATA包裹(<value><![CDATA[{}]]></value>),两种方式均可解决语法问题。
  2. 修复逻辑错误:移除Authorization头赋值中的Bearer 前缀,直接使用原请求头的完整值,避免重复前缀导致的认证失败。

内容的提问来源于stack exchange,提问作者goc

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 06:44:50