Azure中AD令牌访问存储账户未按预期90分钟过期的原因及含义咨询
问题解析与解答
代码示例
from azure.identity import ClientSecretCredential import time token_credential = ClientSecretCredential( "",# tenant id "",# active directory application id "", # active directory application secret ) blob_service_client = BlobServiceClient(account_url=oauth_url, credential=token_credential) def listcontainer(): from azure.storage.blob import BlobServiceClient con = blob_service_client.list_containers() for x in con: print(x) start = int(time.time()) while True: end = int(time.time()) if end - start > 4800: break else: print("run time in minute: ", (end - start) / 60) try: listcontainer() except Exception as e: print("exception reached") print(e) break time.sleep(60)
问题背景
仅初始化一次BlobServiceClient,预期90分钟后会因令牌过期触发异常,但实际并未出现异常。结合文档中“访问令牌默认生命周期为60-90分钟随机值(平均75分钟)”的描述,想明确此场景下的令牌过期具体含义。
为什么未触发预期异常?
你使用的ClientSecretCredential属于Azure Identity SDK的凭据类型,内置自动令牌刷新机制:
- 凭据会缓存当前有效的访问令牌,每次调用Azure服务(如
list_containers)时,会先检查令牌是否有效或即将过期。 - 若令牌已过期或临近过期,它会自动用你提供的租户ID、应用ID和应用密钥,向Azure AD重新请求新的访问令牌。
- 因此
BlobServiceClient每次发起请求时,都能获取到有效的令牌,不会触发令牌过期异常。
此场景下的令牌过期具体含义
这里的“令牌过期”指单个访问令牌本身的生命周期终结:
- Azure AD颁发的每一个访问令牌都有固定有效期(60-90分钟随机分配),一旦超过这个时间,该特定令牌会被Azure服务拒绝,无法用于身份验证和资源请求。
- 但你无需手动处理过期问题,
ClientSecretCredential会自动完成令牌的刷新与替换,对上层的BlobServiceClient和业务代码完全透明。
内容的提问来源于stack exchange,提问作者Kevin
相关产品推荐
相关产品推荐

