You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SAS URL本地正常但生产环境认证失败问题求助

问题:Azure Blob SAS URL生产环境验证失败

代码实现

用于生成Blob SAS URL的Python代码:

def get_signed_url(container, blobPath):
 return generate_blob_sas(
     account_name=azure_account_name,
     account_key=azure_account_key,
     container_name=container,
     blob_name=blobPath,
     permission=BlobSasPermissions(read=True),
     expiry=datetime.utcnow() + timedelta(days=1),
     startsOn=datetime.utcnow() - timedelta(days=1),
     version='2021-10-04',
     protocol='https'
 )

问题现象

  • 本地运行生成的SAS URL可正常访问,示例URL:
    https://production.blob.core.windows.net/organization-134/2031dfac-0a29-4a73-b344-e5aec4e20282/How_to_send_a_request_in_Postman_1.png?se=2023-12-07T12%3A11%3A46Z&sp=r&spr=https&sv=2023-08-03&sr=b&sig=pPHMDdGqQZUrQ2s3YxLuWhkW%2BaPi1zJvyTSWQX2%2Bx2Y%3D
  • 部署到生产环境后,浏览器返回认证失败错误:
<Error>
 <div id="in-page-channel-node-id" data-channel-name="in_page_channel__KbVHh"/>
 <Code>AuthenticationFailed</Code>
 <Message>Server failed to authenticate the request. Make sure the value of Authorization header      is formed correctly including the signature. RequestId:9c8117fc-c01e-0048-4642-28fc5a000000 Time:2023-12-06T12:50:21.7240095Z</Message>
 <AuthenticationErrorDetail>Signature did not match. String to sign used was r 2023-12-07T12:11:46Z /blob/production/organization-134/2031dfac-0a29-4a73-b344-e5aec4e20282/How_to_send_a_request_in_Postman_1.png https 2023-08-03 b </AuthenticationErrorDetail>

已排查情况

存储账户与Python服务均部署在Azure,已排除网络问题和服务器时间差异问题。

解决建议

  • 核对存储账户密钥:确认生产环境配置的azure_account_key与本地完全一致,检查是否存在复制错误、特殊字符转义问题,密钥大小写需严格匹配。
  • 统一SAS版本参数:代码中指定的version='2021-10-04',但生成的URL显示sv=2023-08-03,版本不匹配会导致签名逻辑不一致。建议移除version参数让SDK自动适配存储账户默认版本,或显式指定与存储账户兼容的版本。
  • 验证Blob路径一致性:检查生产环境中blobPath是否存在多余斜杠、大小写错误或编码问题,Azure Blob存储路径区分大小写,签名生成时的路径必须与实际Blob路径完全一致。
  • 检查存储账户访问策略:确认存储账户未开启防火墙或虚拟网络限制拦截SAS请求,即使在Azure内部,未配置允许的规则也会导致请求被拒。同时确认存储账户允许SAS授权访问。
  • 规范时间参数使用:虽然排除了时间差,仍建议使用datetime.datetime.now(datetime.timezone.utc)替代utcnow(),确保时间参数为带时区的UTC时间,避免潜在的时区解析问题。
  • 统一SDK版本:检查本地与生产环境的azure-storage-blob SDK版本是否一致,不同版本的generate_blob_sas方法可能存在参数差异,建议升级至最新稳定版并保持环境一致。

内容的提问来源于stack exchange,提问作者sabstain pru

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 13:06:32