You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure文档翻译权限异常:无法访问源文档位置求助

Azure文档翻译权限错误排查与解决

问题概述

在Azure存储创建了original和transcribed两个容器用于文档翻译,已实现UploadToAzureBlobStorage方法成功将文档上传至original容器,但调用TranslatorAsync方法执行翻译时,抛出Azure.RequestFailedException异常:

'Cannot access source document location with the current permissions. Status: 200 (OK) ErrorCode: InvalidRequest'
且直接访问源文档URL时也出现错误。

相关代码

上传方法

public async Task<Uri> UploadToAzureBlobStorage(string FilePath) {

        ContainerClient = new BlobContainerClient(ConectionString, Constants.AZURE_CONTAINER_ORIGINAL_DOCUMENT);

        var blob = ContainerClient.GetBlobClient(Path.GetFileName(FilePath));
        await blob.UploadAsync(FilePath, true);

        return new Uri($"https://transcribemedocs.blob.core.windows.net/original/{Path.GetFileName(FilePath)}");
    }

翻译方法

public static async Task TranslatorAsync(Uri sourceUrl, Uri TargetUrl, string language = "en") {

        DocumentTranslationClient client = new(new Uri(Constants.ENDPOINT), new AzureKeyCredential(Constants.KEY));

        var input = new DocumentTranslationInput(sourceUrl, TargetUrl, language);

        DocumentTranslationOperation operation = await client.StartTranslationAsync(input);

        await operation.WaitForCompletionAsync();

    }

解决方案

1. 生成带SAS令牌的源文件URL

默认Azure Blob容器为私有访问权限,直接构造的裸URL无法被翻译服务访问,必须生成包含读取权限的SAS令牌:

public async Task<Uri> UploadToAzureBlobStorage(string FilePath) {
    ContainerClient = new BlobContainerClient(ConectionString, Constants.AZURE_CONTAINER_ORIGINAL_DOCUMENT);
    var blob = ContainerClient.GetBlobClient(Path.GetFileName(FilePath));
    await blob.UploadAsync(FilePath, true);

    // 配置SAS令牌参数
    var sasBuilder = new BlobSasBuilder {
        BlobContainerName = blob.BlobContainerName,
        BlobName = blob.Name,
        ExpiresOn = DateTimeOffset.UtcNow.AddHours(24) // 根据业务需求调整有效期
    };
    sasBuilder.SetPermissions(BlobSasPermissions.Read); // 翻译服务仅需读取权限

    // 生成SAS令牌并拼接成可访问的URL
    var credential = new Azure.Storage.StorageSharedKeyCredential(ContainerClient.AccountName, ContainerClient.AccountKey);
    string sasToken = sasBuilder.ToSasQueryParameters(credential).ToString();
    return new Uri($"{blob.Uri}?{sasToken}");
}

2. 生成带写入权限SAS令牌的目标URL

翻译服务需要将翻译后的文件写入transcribed容器,因此目标URL也需包含写入权限的SAS令牌:

// 示例:生成目标Blob的SAS URL
public Uri GetTargetSasUrl(string originalFileName) {
    string targetBlobName = $"{Path.GetFileNameWithoutExtension(originalFileName)}_translated.pdf"; // 自定义翻译后文件名
    var targetContainerClient = new BlobContainerClient(ConectionString, Constants.AZURE_CONTAINER_TRANSCRIBED_DOCUMENT);
    var targetBlobClient = targetContainerClient.GetBlobClient(targetBlobName);

    var sasBuilder = new BlobSasBuilder {
        BlobContainerName = targetBlobClient.BlobContainerName,
        BlobName = targetBlobClient.Name,
        ExpiresOn = DateTimeOffset.UtcNow.AddHours(24)
    };
    sasBuilder.SetPermissions(BlobSasPermissions.Write); // 赋予写入权限

    var credential = new Azure.Storage.StorageSharedKeyCredential(targetContainerClient.AccountName, targetContainerClient.AccountKey);
    string sasToken = sasBuilder.ToSasQueryParameters(credential).ToString();
    return new Uri($"{targetBlobClient.Uri}?{sasToken}");
}

3. 验证存储账户网络访问设置

  • 若存储账户配置了防火墙或虚拟网络规则,需确保Azure认知服务(文档翻译)的IP地址被允许访问,或启用允许受信任的Microsoft服务访问此存储账户选项。
  • 避免将容器设置为公共访问(存在安全风险),私有容器配合SAS令牌是合规方案。

4. 关于异常状态码200的说明

异常中显示的Status:200是翻译服务的外层响应码,实际错误原因仍是源/目标URL的权限不足,无需纠结此状态码,重点修复SAS令牌问题即可。

内容的提问来源于stack exchange,提问作者edu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 19:35:24