Python中azure.ai.translation.document权限问题:无法访问源文档
Azure文档翻译服务权限错误排查(InvalidDocumentAccessLevel)
问题概述
已配置Azure翻译服务及含两个容器的Blob存储,通过用户委托密钥生成SAS连接:源容器赋予读取/列出权限,目标容器赋予写入/列出权限。运行官方示例代码后,源Blob文件未被翻译保存到目标容器,报错:
azure.core.exceptions.HttpResponseError: (InvalidDocumentAccessLevel): Cannot access source document location with the current permissions.
运行环境为企业Windows系统+Thonny工具,怀疑公司云代理可能影响功能。
使用的示例代码如下:
import os from azure.core.credentials import AzureKeyCredential from azure.ai.translation.document import DocumentTranslationClient key = "<your-key>" endpoint = "<your-custom-endpoint>" sourceUrl = "<your-container-sourceUrl>" targetUrl = "<your-container-targetUrl>" client = DocumentTranslationClient(endpoint, AzureKeyCredential(key)) poller = client.begin_translation(sourceUrl, targetUrl, "fr") result = poller.result() print("Status: {}".format(poller.status())) print("Created on: {}".format(poller.details.created_on)) print("Last updated on: {}".format(poller.details.last_updated_on)) print("Total number of translations on documents: {}".format(poller.details.documents_total_count)) print("\nOf total documents...") print("{} failed".format(poller.details.documents_failed_count)) print("{} succeeded".format(poller.details.documents_succeeded_count)) for document in result: print("Document ID: {}".format(document.id)) print("Document status: {}".format(document.status)) if document.status == "Succeeded": print("Source document location: {}".format(document.source_document_url)) print("Translated document location: {}".format(document.translated_document_url)) print("Translated to language: {}\n".format(document.translated_to)) else: print("Error Code: {}, Message: {}\n".format(document.error.code, document.error.message))
排查步骤
1. 验证SAS URL有效性
- 确认源容器SAS包含**读取(r)和列出(l)权限,目标容器SAS包含写入(w)和列出(l)**权限,权限参数无遗漏
- 检查SAS的有效期范围,确保当前时间在SAS生效时段内
- 手动访问源SAS URL(如浏览器中打开),确认能正常下载Blob文件,排除URL本身无效的问题
2. 检查用户委托密钥配置
- 确认生成用户委托密钥时,授予的权限覆盖了容器及Blob的对应操作:源容器需允许读取Blob,目标容器需允许写入Blob
- 验证用户委托密钥本身未过期,生成SAS时使用的密钥为有效状态
3. 代码URL格式校验
- 确保
sourceUrl和targetUrl为完整的容器SAS URL,格式应为:https://<storage-account-name>.blob.core.windows.net/<container-name>?<sas-token> - 检查URL是否存在空格、截断或特殊字符,确保SAS token完整复制
4. 企业代理环境适配
- 在Thonny中配置公司代理:进入
工具 > 选项 > 网络,填入代理地址、端口(如需认证,补充用户名和密码) - 测试网络连通性,运行以下代码验证能否访问Blob存储和翻译服务:
import requests # 测试源Blob访问 res = requests.get(sourceUrl) print(f"源Blob访问状态码: {res.status_code}") # 返回200表示正常 # 测试翻译服务端点访问 res = requests.get(endpoint) print(f"翻译服务访问状态码: {res.status_code}") - 若代理需SSL证书,确认系统已安装对应根证书,避免SSL验证失败
5. 翻译服务网络权限检查
- 登录Azure门户,进入翻译服务的
网络设置,检查是否启用IP白名单。若有白名单,需将企业网络的出口IP添加至允许列表
内容的提问来源于stack exchange,提问作者Laurence Arbin
相关产品推荐
相关产品推荐

