Azure文档翻译权限异常:无法访问源文档位置求助
Azure文档翻译权限错误排查与解决
问题概述
在Azure存储创建了original和transcribed两个容器用于文档翻译,已实现UploadToAzureBlobStorage方法成功将文档上传至original容器,但调用TranslatorAsync方法执行翻译时,抛出Azure.RequestFailedException异常:
'Cannot access source document location with the current permissions. Status: 200 (OK) ErrorCode: InvalidRequest'
且直接访问源文档URL时也出现错误。
相关代码
上传方法
public async Task<Uri> UploadToAzureBlobStorage(string FilePath) { ContainerClient = new BlobContainerClient(ConectionString, Constants.AZURE_CONTAINER_ORIGINAL_DOCUMENT); var blob = ContainerClient.GetBlobClient(Path.GetFileName(FilePath)); await blob.UploadAsync(FilePath, true); return new Uri($"https://transcribemedocs.blob.core.windows.net/original/{Path.GetFileName(FilePath)}"); }
翻译方法
public static async Task TranslatorAsync(Uri sourceUrl, Uri TargetUrl, string language = "en") { DocumentTranslationClient client = new(new Uri(Constants.ENDPOINT), new AzureKeyCredential(Constants.KEY)); var input = new DocumentTranslationInput(sourceUrl, TargetUrl, language); DocumentTranslationOperation operation = await client.StartTranslationAsync(input); await operation.WaitForCompletionAsync(); }
解决方案
1. 生成带SAS令牌的源文件URL
默认Azure Blob容器为私有访问权限,直接构造的裸URL无法被翻译服务访问,必须生成包含读取权限的SAS令牌:
public async Task<Uri> UploadToAzureBlobStorage(string FilePath) { ContainerClient = new BlobContainerClient(ConectionString, Constants.AZURE_CONTAINER_ORIGINAL_DOCUMENT); var blob = ContainerClient.GetBlobClient(Path.GetFileName(FilePath)); await blob.UploadAsync(FilePath, true); // 配置SAS令牌参数 var sasBuilder = new BlobSasBuilder { BlobContainerName = blob.BlobContainerName, BlobName = blob.Name, ExpiresOn = DateTimeOffset.UtcNow.AddHours(24) // 根据业务需求调整有效期 }; sasBuilder.SetPermissions(BlobSasPermissions.Read); // 翻译服务仅需读取权限 // 生成SAS令牌并拼接成可访问的URL var credential = new Azure.Storage.StorageSharedKeyCredential(ContainerClient.AccountName, ContainerClient.AccountKey); string sasToken = sasBuilder.ToSasQueryParameters(credential).ToString(); return new Uri($"{blob.Uri}?{sasToken}"); }
2. 生成带写入权限SAS令牌的目标URL
翻译服务需要将翻译后的文件写入transcribed容器,因此目标URL也需包含写入权限的SAS令牌:
// 示例:生成目标Blob的SAS URL public Uri GetTargetSasUrl(string originalFileName) { string targetBlobName = $"{Path.GetFileNameWithoutExtension(originalFileName)}_translated.pdf"; // 自定义翻译后文件名 var targetContainerClient = new BlobContainerClient(ConectionString, Constants.AZURE_CONTAINER_TRANSCRIBED_DOCUMENT); var targetBlobClient = targetContainerClient.GetBlobClient(targetBlobName); var sasBuilder = new BlobSasBuilder { BlobContainerName = targetBlobClient.BlobContainerName, BlobName = targetBlobClient.Name, ExpiresOn = DateTimeOffset.UtcNow.AddHours(24) }; sasBuilder.SetPermissions(BlobSasPermissions.Write); // 赋予写入权限 var credential = new Azure.Storage.StorageSharedKeyCredential(targetContainerClient.AccountName, targetContainerClient.AccountKey); string sasToken = sasBuilder.ToSasQueryParameters(credential).ToString(); return new Uri($"{targetBlobClient.Uri}?{sasToken}"); }
3. 验证存储账户网络访问设置
- 若存储账户配置了防火墙或虚拟网络规则,需确保Azure认知服务(文档翻译)的IP地址被允许访问,或启用
允许受信任的Microsoft服务访问此存储账户选项。 - 避免将容器设置为公共访问(存在安全风险),私有容器配合SAS令牌是合规方案。
4. 关于异常状态码200的说明
异常中显示的Status:200是翻译服务的外层响应码,实际错误原因仍是源/目标URL的权限不足,无需纠结此状态码,重点修复SAS令牌问题即可。
内容的提问来源于stack exchange,提问作者edu
相关产品推荐
相关产品推荐

