Azure Tables REST授权头异常:DELETE/PUT请求签名验证失败
当使用SharedKeyLite认证调用Azure Table Storage的单个实体操作(PUT更新、DELETE删除)时,签名字符串的资源部分必须包含完整的实体标识路径,也就是带PartitionKey和RowKey的表名后缀,而非单纯的表名或表名加()。
正确的签名字符串生成逻辑
将签名字符串中的表名替换为表名(PartitionKey='分区键值', RowKey='行键值')的完整格式,代码示例如下:
// 替换为实际的分区键和行键值 string partitionKey = "YourPartitionKeyValue"; string rowKey = "YourRowKeyValue"; // 构造完整的实体资源路径 string entityResource = $"{Table}(PartitionKey='{partitionKey}', RowKey='{rowKey}')"; string stringToSign = string.Format("{0}\n/{1}/{2}", date, account, entityResource); var hasher = new HMACSHA256(sharedKey); string signedSignature = Convert.ToBase64String(hasher.ComputeHash(Encoding.UTF8.GetBytes(stringToSign))); string authorizationHeader = string.Format("{0} {1}:{2}", "SharedKeyLite", account, signedSignature);
有效签名字符串示例
假设账户名为MyStorageAccount,表名为Benefits,分区键为User001,行键为HealthPlan,签名字符串应为:
Sun, 01 Jan 2023 17:05:30 GMT\n/MyStorageAccount/Benefits(PartitionKey='User001', RowKey='HealthPlan')
关键注意事项
- 确保PartitionKey和RowKey的取值与请求URL中的完全一致,包括引号、大小写和特殊字符(签名是严格匹配的)
- 不需要对PartitionKey和RowKey进行URL编码,直接使用原始字符串值构造实体路径即可
内容的提问来源于stack exchange,提问作者haPartnerships
相关产品推荐
相关产品推荐

