You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Azure DataLakeServiceClient下载OneLake文件成功数次后遇Forbidden错误

问题:OneLake文件下载授权突然失败(此前多次成功)

场景概述

使用Python通过azure.storage.filedatalake库从OneLake下载Power BI上传的文件,代码及环境配置曾多次成功,但数分钟后突然返回Forbidden授权错误,期间无任何配置变动。

代码实现

from azure.storage.filedatalake import DataLakeServiceClient
from azure.identity import DefaultAzureCredential

WORKSPACE_NAME = "workspace_2"
DATA_PATH = "DataflowsStagingLakehouse.Lakehouse/Files/logo.png"
account_url = f"https://onelake.dfs.fabric.microsoft.com"

token_credential = DefaultAzureCredential()
service_client = DataLakeServiceClient(account_url, credential=token_credential)
file_system_client = service_client.get_file_system_client(WORKSPACE_NAME)
stream = file_system_client.get_file_client(DATA_PATH).download_file()
data = stream.readall()
with open("tmp.png", "wb") as f:
    f.write(data)

已完成的配置

  • 在Azure门户创建名为Eddie's App 2的应用注册
  • 为该应用注册创建客户端密钥
  • 设置环境变量AZURE_TENANT_ID、AZURE_CLIENT_ID、AZURE_CLIENT_SECRET
  • 将应用注册添加为工作区查看者

错误信息

azure.core.exceptions.HttpResponseError: User is not authorized to perform current operation for workspace 'some-uuid-xxxxxxx-xxxxxx' and artifact 'some-uuid-ooooooo-oooooo'
ErrorCode:Forbidden

时间线

  • 10:23:29 下载成功
  • 10:29:42 下载成功
  • 10:37:10 下载失败

排查与解决方法

1. 强制刷新令牌,排除缓存问题

DefaultAzureCredential的令牌缓存可能出现异常,直接重启应用触发令牌重新获取;也可以在代码中添加日志验证令牌有效性:

from azure.identity import DefaultAzureCredential
import logging

logging.basicConfig(level=logging.DEBUG)
credential = DefaultAzureCredential(logging_enable=True)
token = credential.get_token("https://storage.azure.com/.default")
print(f"Token expires on: {token.expires_on}")

2. 确认应用权限未被撤销

  • 登录Fabric门户,进入目标工作区的访问设置,检查Eddie's App 2的查看者权限是否存在
  • 在Azure门户的应用注册中,添加Microsoft Fabric API的Workspace.Read.All或Storage.Read.All应用权限(需租户管理员同意),补充更明确的访问权限

3. 检查Lakehouse路径的权限继承

目标文件所在的Lakehouse可能未继承工作区权限:

  • 进入Lakehouse的管理->权限页面,确认Eddie's App 2是否拥有读取权限
  • 若文件由Power BI数据流上传,检查数据流的输出权限是否限制了应用访问

4. 排查Fabric服务临时故障

查看Microsoft 365服务状态页面,确认OneLake/Fabric服务是否存在临时中断;等待10-15分钟后重新测试,排除服务端授权策略波动的影响

5. 优化代码的令牌处理逻辑

手动管理令牌获取,避免依赖默认缓存的潜在问题:

from azure.storage.filedatalake import DataLakeServiceClient
from azure.identity import DefaultAzureCredential

def get_datalake_client():
    credential = DefaultAzureCredential()
    token = credential.get_token("https://storage.azure.com/.default")
    return DataLakeServiceClient(
        account_url="https://onelake.dfs.fabric.microsoft.com",
        credential=token.token
    )

service_client = get_datalake_client()
file_system_client = service_client.get_file_system_client("workspace_2")
stream = file_system_client.get_file_client("DataflowsStagingLakehouse.Lakehouse/Files/logo.png").download_file()
data = stream.readall()
with open("tmp.png", "wb") as f:
    f.write(data)

内容的提问来源于stack exchange,提问作者Griiid

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 23:52:44