Azure Data Lake Storage Gen2文件夹SAS令牌列表权限HTTP GET请求遇AuthorizationPermissionMismatch错误,咨询文件夹列表特定参数
Great question—this is a super common gotcha with ADLS Gen2's hierarchical namespace (HNS) vs. standard blob storage containers. Let’s break this down clearly:
First, yes—listing an ADLS Gen2 folder does require specific parameters that differ from listing a container, and your AuthorizationPermissionMismatch error is almost certainly tied to using container-focused parameters with a directory-scoped SAS.
Key Difference from Container Listing
ADLS Gen2 treats folders as first-class "directory" resources (thanks to HNS), not just virtual paths under a container. That means the restype=container parameter you use for container listing won’t work here—it tells the service you’re targeting a container, not a nested directory.
Correct Parameters for Folder Listing
To list the contents of an ADLS Gen2 folder via HTTP GET, you need to:
- Replace
restype=containerwithresource=directory - Keep
comp=listto trigger the listing operation - Ensure your SAS token is scoped to the directory (not the container or a single file) with the right permissions
Example Working Request URL
https://<your-storage-account>.dfs.core.windows.net/<your-container>/your/target/folder?comp=list&resource=directory&<your-sas-token>
Critical SAS Token Checks
Double-check your SAS has these non-negotiable settings:
- Resource type:
sr=d(stands for directory—if you seesr=cfor container, it won’t work with a directory-specific request) - Permissions: Must include
l(list) andr(read)—the list operation needs read access to the directory’s metadata and list access to its contents - Scope: The SAS should be generated specifically for your target folder (not the root container) to avoid permission misalignment
Why Your Original Request Failed
When you used restype=container, the storage service tried to interpret your folder path as a container (which it isn’t). Combined with a directory-scoped SAS, this created a permission mismatch—your SAS is authorized for directory operations, not container-level listing.
内容的提问来源于stack exchange,提问作者AnotherGeek

