You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Azure CDN下载Blob授权失败,本地及直连存储正常求助

Azure App Service通过CDN访问Blob报403认证错误排查

问题现象

本地运行API时,通过Azure CDN端点下载Blob正常;发布到Azure App Service后,收到403认证错误:

Server failed to authenticate the request. Make sure the value of Authorization header is formed correctly including the signature.
RequestId:xxx
Time:2022-12-22T12:45:13.3900743Z
Status: 403 (Server failed to authenticate the request. Make sure the value of Authorization header is formed correctly including the signature.)
ErrorCode: AuthenticationFailed
AuthenticationErrorDetail: The MAC signature found in the HTTP request 'xx' is not the same as any computed signature. Server used following string to sign: 'GET
bytes=0-8388607
x-ms-client-request-id:xxxx
x-ms-date:Thu, 22 Dec 2022 12:45:13 GMT
x-ms-range:bytes=0-268435455
x-ms-return-client-request-id:true
x-ms-version:2021-08-06
/xx/stagecontainer/18'.

直接使用Blob存储URI在App Service上运行API无报错。

核心原因

CDN在转发请求时添加了额外的HTTP请求头,导致Blob存储服务用于验证签名的字符串和API代码计算签名时使用的字符串不一致。

从错误信息的签名字符串可见,同时存在bytes=0-8388607和x-ms-range:bytes=0-268435455两个范围请求头:

  • 本地请求未经过CDN,仅包含x-ms-range头,代码基于该头计算的签名能通过验证;
  • 请求经过CDN后,CDN自动添加了标准Range(或bytes)头,Blob服务收到的请求头多了一项,用包含新头的字符串重新计算签名,与API发送的签名不匹配,触发403错误。

解决方案

  1. 检查CDN转发/优化设置

    • 查看CDN的缓存规则或范围请求优化配置,确认是否自动添加了Range/bytes头。若使用Azure CDN from Microsoft,尝试禁用“范围请求优化”功能后重试。
    • 检查CDN规则引擎中的自定义规则,若存在修改、添加请求头的配置,调整或删除相关规则。
  2. 调整API签名计算逻辑

    • 修改代码中生成Authorization头的逻辑,确保包含所有可能被CDN添加的请求头;或捕获CDN转发后的实际请求头,基于这些头重新计算签名。
  3. 验证CDN请求转发完整性

    • 用Fiddler、Postman等工具分别捕获本地请求、App Service通过CDN发送的请求,对比请求头差异,确认CDN的修改项后针对性调整配置或代码。

内容的提问来源于stack exchange,提问作者Malin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 01:05:19