Azure Blob Storage REST API 403认证失败:Postman上传文件签名问题
Azure Blob Storage Postman上传认证失败问题及解决
问题场景
尝试通过Postman发送PUT请求将文件上传至Azure Blob Storage,始终无法完成认证,查阅官方文档及相关社区帖子后仍无法正确生成签名。
Postman请求头配置

预请求签名生成脚本
const crypto = require('crypto-js'); const date = new Date().toUTCString(); const method = "PUT"; const containerName = "media"; const x_ms_version = "2015-12-11"; const accountName = "revistaregion"; const blobName = "revista-region-original.png"; const accountKey = "olOuS5cG...................."; const xmsHeader = `x-ms-blob-type:BlockBlob\nx-ms-date:${date}\nx-ms-version:${x_ms_version}`; const resHeader = `/${containerName}/${blobName}`; const stringToSign = method + "\n" + "\n" + //Content Encoding "\n" + //Content Language "717\n" + //Content Length "\n" + //Content MD5 "image/png\n" + //Content Type "\n" + //Date "\n" + //If - Modified - Since "\n" + //If - Match "\n" + //If - None - Match "\n" + //If - Unmodified - Since "\n" + //Range + xmsHeader + resHeader; const signature = crypto.HmacSHA256(crypto.enc.Utf8.parse(stringToSign), crypto.enc.Base64.parse(accountKey)); const signatureBase64 = crypto.enc.Base64.stringify(signature); const authorizationHeader = `SharedKey ${accountName}:${signatureBase64}`; pm.environment.set("authorizationHeader", authorizationHeader) pm.environment.set("time", date)
错误响应
<?xml version="1.0" encoding="utf-8"?> <Error> <Code>AuthenticationFailed</Code> <Message>Server failed to authenticate the request. Make sure the value of Authorization header is formed correctly including the signature. RequestId:97e7b328-001e-0001-14f0-471dd1000000 Time:2024-01-15T20:24:11.2993548Z</Message> <AuthenticationErrorDetail>The MAC signature found in the HTTP request 'WPGDEOMEQ06F7L9Nhog3BwuIRZMFRnOVEalDOLMf3yI=' is not the same as any computed signature. Server used following string to sign: 'PUT 717 image/png x-ms-blob-type:BlockBlob x-ms-date:Mon, 15 Jan 2024 20:24:10 GMT x-ms-version:2015-12-11 /revistaregion/media/revista-region-original.png'.</AuthenticationErrorDetail> </Error>
问题解决
对比正确实现后,定位到两个关键问题:
- 资源路径构造错误:
原代码中资源路径缺少存储账户名称:
正确的路径需要包含账户名:const resHeader = `/${containerName}/${blobName}`;const resHeader = `/${accountName}/${containerName}/${blobName}`; - 请求头缺失:在Postman请求中添加
Content-type和Content-Length请求头,并确保签名字符串(stringToSign)的构造与服务器预期一致后,认证问题解决。
内容的提问来源于stack exchange,提问作者C. Mateo Martinez G.
相关产品推荐
相关产品推荐

