You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用SAS URL分块传文件至Azure Blob时遇403权限错误求助

排查分块上传Blob时的403权限错误

1. 检查SAS URL的权限配置

你的示例SAS URL权限为sp=rc,仅包含**读取(r)和创建(c)**权限,但分块上传的核心操作需要以下权限:

  • w(写入):用于执行上传块(Put Block)和提交块列表(Put Block List)操作
  • 若需要覆盖已有Blob,还需额外添加d(删除)权限

修正Python生成SAS的代码,确保权限至少包含rcw:

from azure.storage.blob import generate_blob_sas, BlobSasPermissions

# 配置读取、创建、写入权限
sas_permissions = BlobSasPermissions(read=True, create=True, write=True)
sas_url = generate_blob_sas(
    account_name="testvideos",
    container_name="testvideos",
    blob_name="user_125/video_125/test.mp4",
    account_key="your_account_key",
    permission=sas_permissions,
    expiry="2023-05-14T11:02:59Z"
)

2. 验证请求头配置

分块上传的两个核心步骤必须携带正确的请求头,否则会触发权限或格式错误:

上传块(Put Block)

  • 必须设置x-ms-blob-type: BlockBlob
  • 块ID需为Base64编码的字符串(长度1-64字节)
  • React示例代码:
async function uploadBlock(blockId, chunk, sasUrl) {
  const encodedBlockId = btoa(blockId); // 对块ID进行Base64编码
  const blockUrl = `${sasUrl.split('?')[0]}?comp=block&blockid=${encodedBlockId}&${sasUrl.split('?')[1]}`;
  
  const response = await fetch(blockUrl, {
    method: 'PUT',
    headers: {
      'x-ms-blob-type': 'BlockBlob',
      'Content-Length': chunk.size.toString()
    },
    body: chunk
  });
  
  if (!response.ok) {
    throw new Error(`上传块失败: ${await response.text()}`);
  }
  return encodedBlockId;
}

提交块列表(Put Block List)

  • 需发送XML格式的块列表,并设置Content-Type: application/xml
  • React示例代码:
async function commitBlockList(blockIds, sasUrl) {
  const commitUrl = `${sasUrl.split('?')[0]}?comp=blocklist&${sasUrl.split('?')[1]}`;
  const blockListXml = `<?xml version="1.0" encoding="utf-8"?>
<BlockList>
  ${blockIds.map(id => `<Latest>${id}</Latest>`).join('')}
</BlockList>`;

  const response = await fetch(commitUrl, {
    method: 'PUT',
    headers: {
      'Content-Type': 'application/xml',
      'Content-Length': blockListXml.length.toString()
    },
    body: blockListXml
  });
  
  if (!response.ok) {
    throw new Error(`提交块列表失败: ${await response.text()}`);
  }
}

3. 其他排查点

  • 确认SAS URL有效期:上传过程中SAS未过期(建议设置几小时的有效期,避免中途失效)
  • 核对Blob路径:生成SAS的Blob名称需与上传目标路径完全一致
  • 检查参数重复:手动拼接URL时避免重复出现?或相同参数键

内容的提问来源于stack exchange,提问作者CloudExplorer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 02:50:13