You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Logic Apps中Create SAS URI by Path连接器AAD认证报错求解决

问题说明

Create SAS URI by Path 连接器存在设计限制,不支持Azure AD或托管身份认证,只能通过存储账户密钥的连接方式使用,这就是你遇到报错的根本原因,没有直接修复该连接器的方法,以下是可行的替代方案:

替代方案

方案1:通过Azure Functions生成User Delegation SAS URI

  • 创建启用系统托管身份的Azure Function,给该托管身份分配存储账户的Blob Data Contributor角色(至少需要读取Blob及生成User Delegation SAS的权限)
  • 在Function中使用Azure.Storage.Blobs SDK编写代码,接收Blob容器名、路径等参数,通过托管身份获取Blob客户端,生成基于AAD身份的User Delegation SAS(无需账户密钥)
  • 在Logic App中添加Azure Functions连接器,调用该Function传入参数,获取返回的SAS URI

示例C# Function代码:

using Azure.Storage.Blobs;
using Azure.Storage.Sas;
using Microsoft.AspNetCore.Http;
using Microsoft.AspNetCore.Mvc;
using Microsoft.Azure.WebJobs;
using Microsoft.Azure.WebJobs.Extensions.Http;
using Microsoft.Extensions.Logging;
using System;
using System.Threading.Tasks;

public static class GenerateBlobSas
{
    [FunctionName("GenerateBlobSas")]
    public static async Task<IActionResult> Run(
        [HttpTrigger(AuthorizationLevel.Function, "post", Route = null)] HttpRequest req,
        ILogger log)
    {
        string storageAccountName = Environment.GetEnvironmentVariable("StorageAccountName");
        string containerName = req.Query["containerName"];
        string blobPath = req.Query["blobPath"];

        var blobServiceClient = new BlobServiceClient(
            new Uri($"https://{storageAccountName}.blob.core.windows.net"), 
            new Azure.Identity.DefaultAzureCredential());
        
        var userDelegationKey = await blobServiceClient.GetUserDelegationKeyAsync(
            DateTimeOffset.UtcNow, 
            DateTimeOffset.UtcNow.AddHours(1));

        var blobClient = blobServiceClient
            .GetBlobContainerClient(containerName)
            .GetBlobClient(blobPath);
            
        var sasBuilder = new BlobSasBuilder()
        {
            BlobContainerName = containerName,
            BlobName = blobPath,
            Resource = "b",
            ExpiresOn = DateTimeOffset.UtcNow.AddHours(1)
        };
        sasBuilder.SetPermissions(BlobSasPermissions.Read);

        string sasToken = sasBuilder.ToSasQueryParameters(userDelegationKey, storageAccountName).ToString();
        string sasUri = $"{blobClient.Uri}?{sasToken}";

        return new OkObjectResult(sasUri);
    }
}

方案2:在Logic App中调用Storage REST API生成User Delegation SAS

无需额外依赖Function,直接在Logic App内通过HTTP连接器完成:

  1. 添加HTTP连接器,设置请求方法为POST,URL为https://{你的存储账户名}.blob.core.windows.net/?restype=service&comp=userdelegationkey
  2. 认证方式选择Managed Identity,资源设置为https://storage.azure.com/
  3. 请求体传入JSON,指定密钥有效期:
    {
        "SignedStart": "@{utcNow()}",
        "SignedExpiry": "@{addHours(utcNow(), 1)}"
    }
    
  4. 解析返回的UserDelegationKey字段(包含SignedOid、SignedTid、SignedKey等关键信息)
  5. 手动构造SAS签名(需通过Logic App的Compose、HMAC、Base64等操作实现HMAC-SHA256加密),最终拼接成Blob的SAS URI

注意:此方案需要熟悉SAS签名的构造规则,适合对Azure Storage REST API有了解的场景。

方案3:静态网站URL(仅适用于公开访问场景)

如果存储账户启用了静态网站功能,且Blob放在$web容器中,可直接使用静态网站的固定URL访问Blob,无需生成SAS。但该方式仅适合非敏感数据,安全性较低。

内容的提问来源于stack exchange,提问作者Pradeep Jain

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 06:16:20