You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在APIM策略中从Azure Key Vault读取HMAC密钥遇错求助

解决APIM策略中HMAC验证+Key Vault密钥读取的三类错误

错误原因及对应修复方案

1. 'FetchAccessToken' 不存在于当前上下文

APIM策略没有内置FetchAccessToken函数,你参考的代码里的这个函数是自定义实现,最简单的替代方案是使用APIM内置的托管身份认证策略直接获取Key Vault的访问令牌,无需自定义函数。

2. 'object' 类型无'url'定义 & 'object'类型无'Body'定义

这两个错误都是因为对Key Vault API的响应对象类型处理不当:直接将响应存为object类型后,无法通过.访问属性。需要将响应转换为JObject类型(APIM默认集成Newtonsoft.Json),通过索引器或GetValue方法读取属性。


修正后的完整APIM策略代码

<policies>
    <inbound>
        <!-- 1. 用托管身份获取Key Vault访问令牌 -->
        <authentication-managed-identity resource="https://vault.azure.net" output-token-variable-name="kvAccessToken" ignore-error="false" />
        
        <!-- 2. 调用Key Vault API读取密钥 -->
        <send-request mode="new" response-variable-name="kvResponse" timeout="20" ignore-error="false">
            <set-url>https://你的密钥保管库名称.vault.azure.net/secrets/你的密钥名称/?api-version=7.4</set-url>
            <set-method>GET</set-method>
            <set-header name="Authorization" exists-action="override">
                <value>Bearer @((string)context.Variables["kvAccessToken"])</value>
            </set-header>
        </send-request>
        
        <!-- 3. 解析Key Vault返回的密钥值 -->
        <set-variable name="hmacKey" value="@(((JObject)context.Variables["kvResponse"]).GetValue("value").ToString())" />
        
        <!-- 4. HMAC签名验证逻辑(根据实际业务调整算法、签名内容) -->
        <set-variable name="requestPayload" value="@(context.Request.Body.As<string>(preserveContent: true))" />
        <set-variable name="computedHmac" value="@(Convert.ToBase64String(System.Security.Cryptography.HMACSHA256.Create((string)context.Variables["hmacKey"]).ComputeHash(System.Text.Encoding.UTF8.GetBytes((string)context.Variables["requestPayload"]))))" />
        <set-variable name="clientHmac" value="@(context.Request.Headers.GetValueOrDefault("X-HMAC-Signature", ""))" />
        
        <!-- 验证签名不匹配则返回401 -->
        <choose>
            <when condition="@(!string.Equals((string)context.Variables["computedHmac"], (string)context.Variables["clientHmac"], StringComparison.InvariantCultureIgnoreCase))">
                <return-response>
                    <set-status code="401" reason="Unauthorized" />
                    <set-body>Invalid HMAC signature</set-body>
                </return-response>
            </when>
        </choose>
    </inbound>
    <backend>
        <forward-request />
    </backend>
    <outbound>
        <base />
    </outbound>
    <on-error>
        <base />
    </on-error>
</policies>

额外注意事项

  • 确保APIM的系统/用户托管身份已被授予Key Vault的Secret Get权限
  • 替换代码中的你的密钥保管库名称和你的密钥名称为实际值
  • HMAC算法(如SHA256)、签名生成规则(是否包含请求头、时间戳等)需与客户端保持完全一致

内容的提问来源于stack exchange,提问作者Sindhu1990

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 02:33:26