You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure CDN签名URL问题:Node.js生成的PUT请求签名不匹配

问题

使用Node.js生成Azure CDN签名URL时,PUT请求返回“Signature did not match. String to sign used was w”错误。已知:

  • Azure CDN已配置源路径映射,GET请求可正常工作
  • 通过Azure控制台手动生成的签名URL替换为CDN地址后,PUT请求在Postman中能正常执行
  • OPTIONS请求无异常
    当前Node.js代码如下:
const credentials = new storage.StorageSharedKeyCredential(AZURE_STORAGE_ACCOUNT, AZURE_ACCOUNT_KEY);
const blobServiceClient = new storage.BlobServiceClient(AZURE_CDN+"/"+fileName, credentials);
const permissions = new storage.BlobSASPermissions();
permissions.write = true;

const currentDateTime = new Date();
const expiryDateTime = new Date(currentDateTime.setMinutes(currentDateTime.getMinutes()+5));//Expire the SAS token in 5 minutes.

const blobSAS = storage.generateBlobSASQueryParameters({
    startsOn: new Date(),
    expiresOn: expiryDateTime,
    permissions: permissions,
    protocol: storage.SASProtocol.Https
   
},
    credentials
).toString();;
return blobServiceClient.url+ "?" + blobSAS;
};
原因与解决方案

核心问题

生成Blob SAS签名时缺少容器名称(containerName)和Blob名称(blobName)参数。这两个参数是签名字符串的核心组成部分,缺失会导致签名仅包含权限标识"w",与CDN验证时所需的完整签名字符串不匹配,从而触发错误。

修复步骤

  1. 拆分文件路径:从fileName中分离出容器名和Blob名(假设fileName格式为容器名/Blob文件名,如示例中的logos/09b1f812-e46e-4b88-9153-0496c130ccf8.png)
  2. 补充SAS生成参数:在generateBlobSASQueryParameters中添加containerName和blobName
  3. 简化URL拼接:无需通过BlobServiceClient拼接CDN地址,直接用CDN域名+文件路径+SAS参数即可

修改后的代码示例

const credentials = new storage.StorageSharedKeyCredential(AZURE_STORAGE_ACCOUNT, AZURE_ACCOUNT_KEY);
const permissions = new storage.BlobSASPermissions();
permissions.write = true;

// 拆分容器名和Blob名
const [containerName, blobName] = fileName.split('/');

const currentDateTime = new Date();
const expiryDateTime = new Date(currentDateTime.setMinutes(currentDateTime.getMinutes() + 5));

const blobSAS = storage.generateBlobSASQueryParameters({
    containerName: containerName,
    blobName: blobName,
    startsOn: new Date(),
    expiresOn: expiryDateTime,
    permissions: permissions,
    protocol: storage.SASProtocol.Https
}, credentials).toString();

// 直接拼接CDN URL与SAS参数
return `${AZURE_CDN}/${fileName}?${blobSAS}`;
};

补充说明

Azure控制台手动生成SAS时会自动填入容器和Blob信息,因此签名字符串完整,替换CDN地址后可正常使用。而你的代码中未传递这两个关键参数,导致签名逻辑不完整,仅生成了基于权限的部分签名,最终验证失败。

内容的提问来源于stack exchange,提问作者Madhu Nair

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 19:06:32