You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Blob存储UnsupportedHeader(400)错误:请求头不支持问题排查

问题描述

使用Azure.Storage.Blobs 12.18.0版本执行以下代码创建Blob容器时,遇到400 Bad Request错误,错误码UnsupportedHeader,提示请求中的x-ms-blob-public-access头不被支持。

代码示例:

var blobServiceClient = new BlobServiceClient(_connectionString);
var containerClient = blobServiceClient.GetBlobContainerClient(container);
await containerClient.CreateIfNotExistsAsync(PublicAccessType.Blob);

详细错误信息:

One of the headers specified in the request is not supported.
RequestId:80012b75-701c-0040-5aaa-ffd8bc000000
Time:2023-10-15T20:57:42.9066248Z
Status: 400 (One of the headers specified in the request is not supported.)
ErrorCode: UnsupportedHeader

Additional Information:
HeaderName: x-ms-blob-public-access

Content:
<?xml version="1.0" encoding="utf-8"?>
<Error><Code>UnsupportedHeader</Code><Message>One of the headers specified in the request is not supported.
RequestId:80012b75-701c-0040-5aaa-ffd8bc000000
Time:2023-10-15T20:57:42.9066248Z</Message><HeaderName>x-ms-blob-public-access</HeaderName></Error>

Headers:
Server: Windows-Azure-Blob/1.0,Microsoft-HTTPAPI/2.0
x-ms-error-code: UnsupportedHeader
x-ms-request-id: 80012b75-701c-0040-5aaa-ffd8bc000000
x-ms-version: 2020-10-02
x-ms-client-request-id: 83edaa76-9947-4a02-a654-1e368c711c4f
Date: Sun, 15 Oct 2023 20:57:42 GMT
Content-Length: 296
Content-Type: application/xml
问题原因与解决方案

问题原因

这个错误的核心是存储账户类型不支持通过x-ms-blob-public-access头设置公共访问权限:

  • 如果你的存储账户是启用了分层命名空间的Azure Data Lake Storage Gen2(ADLS Gen2)账户,这类账户的权限管理依赖ACL(访问控制列表),而非Blob存储的公共访问模式。代码中传递PublicAccessType参数会触发SDK发送x-ms-blob-public-access头,但ADLS Gen2账户不识别该头,因此返回400错误。
  • 错误返回的x-ms-version:2020-10-02显示,SDK使用的API版本本身支持该请求头,问题出在存储账户类型的兼容性上。

解决方案

根据存储账户使用需求,选择以下方案:

方案1:改用标准Blob存储账户

如果不需要ADLS Gen2的分层目录、精细ACL等特性,可以创建一个不启用分层命名空间的标准Blob存储账户,原代码即可正常运行,PublicAccessType.Blob设置会生效。

方案2:适配ADLS Gen2存储账户

若必须使用ADLS Gen2账户,需修改代码并改用ACL管理权限:

  1. 移除CreateIfNotExistsAsync方法中的PublicAccessType参数,默认创建私有容器:
var blobServiceClient = new BlobServiceClient(_connectionString);
var containerClient = blobServiceClient.GetBlobContainerClient(container);
await containerClient.CreateIfNotExistsAsync();
  1. 若需要类似公共访问的效果,可通过SetAccessPolicyAsync方法配置ACL规则,授予所有用户读取权限:
// 创建ACL规则,允许所有用户读取容器内容
var acl = new List<BlobAccessPolicy>
{
    new BlobAccessPolicy
    {
        Permissions = "r",
        StartsOn = DateTimeOffset.UtcNow,
        ExpiresOn = DateTimeOffset.UtcNow.AddYears(1)
    }
};
await containerClient.SetAccessPolicyAsync(acl);

方案3:检查存储账户配置

确认是否误启用了分层命名空间,若为误操作,可重新创建存储账户并关闭该选项,恢复使用原代码。

内容的提问来源于stack exchange,提问作者Noor All Safaet

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 08:50:32