.NET 8 WebApi部署到APIM访问Azure Blob报403认证失败求助
.NET 8 WebApi部署到APIM后访问Azure Blob存储报403认证失败
我有一个.NET 8 WebApi项目,使用Azure.Storage.Blobs SDK(v12.19.1)通过访问密钥访问Azure存储账户。在本地主机或Azure虚拟机运行时无问题,但部署到API管理服务(APIM)后,操作失败并返回403 (Server failed to authenticate the request. Make sure the value of Authorization header is formed correctly including the signature)。
SDK注册代码
var azureConnectionString = builder.Configuration.GetConnectionString("StorageConnectionString"); services.AddAzureClients(clientBuilder => { clientBuilder.AddBlobServiceClient(azureConnectionString); });
引发异常的代码
var containerClient = _client.GetBlobContainerClient("uploads"); if (!await containerClient.ExistsAsync()) await containerClient.CreateAsync();
连接字符串格式
"StorageConnectionString": "DefaultEndpointsProtocol=https;AccountName={ACCOUNT_NAME};AccountKey={VALUE_REMOVED};EndpointSuffix=core.windows.net"
已排查操作
- 反复检查并轮换了存储账户访问密钥(其他环境正常,排除密钥本身问题)
- 尝试过多个相关技术解决方案
核心差异与疑问
本地主机和Azure虚拟机时区为MSDT(-7),而APIM服务使用UTC时区。根据相关资料,时区差异可能导致此认证错误,但不清楚如何解决始终运行在UTC的API服务的该问题。
堆栈跟踪信息
"Status":403, "ErrorCode":"AuthenticationFailed", "ClassName":"Azure.RequestFailedException", "Message":"Service request failed.\r\nStatus: 403 (Server failed to authenticate the request. Make sure the value of Authorization header is formed correctly including the signature.)\r\n ErrorCode: AuthenticationFailed\r\n\r\n Headers:\r\n Transfer-Encoding: chunked\r\n Server: Microsoft-HTTPAPI/2.0\r\n x-ms-request-id: f7bcf6cf-d01e-002d-3537-3922f1000000\r\n x-ms-error-code: AuthenticationFailed\r\n Date: Thu, 28 Dec 2023 16:53:13 GMT\r\n", "Data":null, "InnerException":null, "HelpURL":null, "StackTraceString":" at Azure.Core.HttpPipelineExtensions.ProcessMessageAsync(HttpPipeline pipeline, HttpMessage message, RequestContext requestContext, CancellationToken cancellationToken)\r\n at Azure.Storage.Blobs.BlobRestClient.GetPropertiesAsync(String snapshot, String versionId, Nullable`1 timeout, String leaseId, String encryptionKey, String encryptionKeySha256, String encryptionAlgorithm, String ifTags, RequestConditions requestConditions, RequestContext context)\r\n at Azure.Storage.Blobs.Specialized.BlobBaseClient.GetPropertiesInternal(BlobRequestConditions conditions, Boolean async, RequestContext context, String operationName)\r\n at Azure.Storage.Blobs.Specialized.BlobBaseClient.ExistsInternal(Boolean async, CancellationToken cancellationToken)\r\n at Azure.Storage.Blobs.Specialized.BlobBaseClient.ExistsAsync(CancellationToken cancellationToken)\r\n at MyDaycareApi.Services.FileManagerService.LoadTemplateAsync(String path) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Services\\FileManagerService.cs:line 138\r\n at MyDaycareApi.Services.ViewRenderService.BuildAndReplaceAsync(String templateName, Dictionary`2 data) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Services\\ViewRenderService.cs:line 19\r\n at MyDaycareApi.Builders.EmailBuilder.BuildNotification(Int32 daycareId, String daycareName, IEnumerable`1 guardians, String title, String message, String btnText, String btnUrl) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Builders\\EmailBuilder.cs:line 132\r\n at MyDaycareApi.Services.AppNotificationService.SendEmailNotificationAsync(Guardian systemUser, Guardian accountHolder, AppNotificationCreateDto dto) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Services\\AppNotificationService.cs:line 61\r\n at MyDaycareApi.Services.AppNotificationService.SendNotificationAsync(AppNotificationCreateDto dto, List`1 accountHoldersToNotify) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Services\\AppNotificationService.cs:line 130\r\n at MyDaycareApi.Services.AppNotificationService.SendAsync(String email, AppNotificationCreateDto dto) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Services\\AppNotificationService.cs:line 158\r\n at MyDaycareApi.Services.MessageService.SendMessageAsync(IIdentity from, IIdentity to, String msg, UploadImageDto image, Boolean doNotSendEmail) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Services\\MessageService.cs:line 320\r\n at MyDaycareApi.Services.MessageService.SendMessage(ILoggedInUser loggedInUser, NewMessageDto model) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Services\\MessageService.cs:line 354\r\n at MyDaycareApi.Controllers.MessagesController.CreateV2Async(NewMessageDto model) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Controllers\\MessagesController.cs:line 107", "RemoteStackTraceString":null, "RemoteStackIndex":0, "ExceptionMethod":null, "HResult":-2146233088, "Source":"Azure.Storage.Blobs", "WatsonBuckets":null
内容的提问来源于stack exchange,提问作者OverMars
相关产品推荐
相关产品推荐

