You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在AWS IAM ListGroup调用中指定PathPrefix时出现签名错误

AWS IAM ListGroups API签名不匹配问题(含PathPrefix=/参数)

问题重现

  • 正常返回结果的请求:
    https://iam.amazonaws.com/?Action=ListGroups&MaxItems=10&Version=2010-05-08
    
  • 添加PathPrefix=/后返回签名错误的请求:
    https://iam.amazonaws.com/?Action=ListGroups&PathPrefix=/&MaxItems=10&Version=2010-05-08
    
    错误提示:

    "The request signature we calculated does not match the signature you provided. Check your AWS Secret Access Key and signing method. Consult the service documentation for details."

问题原因

AWS API签名计算要求所有查询参数的值必须进行URL编码。/属于URL特殊字符,直接作为参数值传递时,签名计算过程中使用的编码后值(%2F)与实际请求中传递的原始值(/)不一致,导致签名验证失败。

解决方法

  1. 对PathPrefix的值进行URL编码:将/替换为编码后的%2F,修改后的请求URL为:
    https://iam.amazonaws.com/?Action=ListGroups&PathPrefix=%2F&MaxItems=10&Version=2010-05-08
    
  2. 同步签名计算逻辑:确保在生成签名时,使用编码后的参数值(%2F)参与签名构建,而非原始的/。只有签名计算和实际请求的参数完全一致,才能通过验证。

额外注意

  • 不要用引号包裹PathPrefix的值,这会被当作参数值的一部分,触发格式错误
  • 对于非默认PathPrefix值(如/dev/),需对每个/进行编码,最终值应为%2Fdev%2F

内容的提问来源于stack exchange,提问作者Gaius Augustus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 10:52:07