You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Python中azure.ai.translation.document权限问题:无法访问源文档

Azure文档翻译服务权限错误排查(InvalidDocumentAccessLevel)

问题概述

已配置Azure翻译服务及含两个容器的Blob存储,通过用户委托密钥生成SAS连接:源容器赋予读取/列出权限,目标容器赋予写入/列出权限。运行官方示例代码后,源Blob文件未被翻译保存到目标容器,报错:

azure.core.exceptions.HttpResponseError: (InvalidDocumentAccessLevel): Cannot access source document location with the current permissions.

运行环境为企业Windows系统+Thonny工具,怀疑公司云代理可能影响功能。

使用的示例代码如下:

import os
from azure.core.credentials import AzureKeyCredential
from azure.ai.translation.document import DocumentTranslationClient

key = "<your-key>"
endpoint = "<your-custom-endpoint>"
sourceUrl = "<your-container-sourceUrl>"
targetUrl = "<your-container-targetUrl>"

client = DocumentTranslationClient(endpoint, AzureKeyCredential(key))

poller = client.begin_translation(sourceUrl, targetUrl, "fr")
result = poller.result()

print("Status: {}".format(poller.status()))
print("Created on: {}".format(poller.details.created_on))
print("Last updated on: {}".format(poller.details.last_updated_on))
print("Total number of translations on documents: {}".format(poller.details.documents_total_count))

print("\nOf total documents...")
print("{} failed".format(poller.details.documents_failed_count))
print("{} succeeded".format(poller.details.documents_succeeded_count))

for document in result:
    print("Document ID: {}".format(document.id))
    print("Document status: {}".format(document.status))
    if document.status == "Succeeded":
        print("Source document location: {}".format(document.source_document_url))
        print("Translated document location: {}".format(document.translated_document_url))
        print("Translated to language: {}\n".format(document.translated_to))
    else:
        print("Error Code: {}, Message: {}\n".format(document.error.code, document.error.message))

排查步骤

1. 验证SAS URL有效性

  • 确认源容器SAS包含**读取(r)和列出(l)权限,目标容器SAS包含写入(w)和列出(l)**权限,权限参数无遗漏
  • 检查SAS的有效期范围,确保当前时间在SAS生效时段内
  • 手动访问源SAS URL(如浏览器中打开),确认能正常下载Blob文件,排除URL本身无效的问题

2. 检查用户委托密钥配置

  • 确认生成用户委托密钥时,授予的权限覆盖了容器及Blob的对应操作:源容器需允许读取Blob,目标容器需允许写入Blob
  • 验证用户委托密钥本身未过期,生成SAS时使用的密钥为有效状态

3. 代码URL格式校验

  • 确保sourceUrl和targetUrl为完整的容器SAS URL,格式应为:https://<storage-account-name>.blob.core.windows.net/<container-name>?<sas-token>
  • 检查URL是否存在空格、截断或特殊字符,确保SAS token完整复制

4. 企业代理环境适配

  • 在Thonny中配置公司代理:进入工具 > 选项 > 网络,填入代理地址、端口(如需认证,补充用户名和密码)
  • 测试网络连通性,运行以下代码验证能否访问Blob存储和翻译服务:
    import requests
    # 测试源Blob访问
    res = requests.get(sourceUrl)
    print(f"源Blob访问状态码: {res.status_code}")  # 返回200表示正常
    # 测试翻译服务端点访问
    res = requests.get(endpoint)
    print(f"翻译服务访问状态码: {res.status_code}")
    
  • 若代理需SSL证书,确认系统已安装对应根证书,避免SSL验证失败

5. 翻译服务网络权限检查

  • 登录Azure门户,进入翻译服务的网络设置,检查是否启用IP白名单。若有白名单,需将企业网络的出口IP添加至允许列表

内容的提问来源于stack exchange,提问作者Laurence Arbin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 10:40:58