如何使用访问密钥为Azure Blob存储PUT BLOB REST API构造Authorization头
Azure Blob REST API 403 认证错误排查结果
经校验你的代码存在以下几处问题,修复后即可解决签名校验失败报错:
- CanonicalizedResource 路径与实际请求不匹配
按照Azure Shared Key签名规范,CanonicalizedResource的格式为/<存储账户名>/<容器名>/<Blob名>,你代码中构造的路径是/pcatest/pca-al/newBlob,但实际请求的URL是https://test.blob.core.windows.net/testcontainer/newblob,二者完全不一致,这是签名校验失败的核心原因。 - CanonicalizedHeaders 末尾缺少换行符
你拼接签名字符串时,CanonicalizedHeaders结束后直接拼接了CanonicalizedResource,按照规范二者之间必须补充一个换行符\n,否则签名字符串格式错误。 - 账户信息一致性校验缺失
签名中使用的存储账户名取的是defaults.accountName,需要确认该值与实际请求URL中的存储账户名test完全一致,同时确认你使用的accountKey是该存储账户的有效访问密钥。 - Content-Type 两边不一致风险
你当前签名字符串中的Content-Type为空值,若请求时fetch自动添加了默认Content-Type值,会导致头信息和签名不匹配,建议显式在请求头和签名字符串中设置相同的Content-Type(比如text/plain)。
以下是修正后的关键代码片段:
// 修正CanonicalizedResource为实际的账户、容器、Blob名 'CanonicalizedResource': '/test/testcontainer/newblob' // 修正签名字符串拼接逻辑 let string_to_sign = (string_params['verb'] + '\n' + string_params['Content-Encoding'] + '\n' + string_params['Content-Language'] + '\n' + string_params['Content-Length'] + '\n' + string_params['Content-MD5'] + '\n' + 'text/plain' + '\n' // 统一Content-Type取值 + string_params['Date'] + '\n' + string_params['If-Modified-Since'] + '\n' + string_params['If-Match'] + '\n' + string_params['If-None-Match'] + '\n' + string_params['If-Unmodified-Since'] + '\n' + string_params['Range'] + '\n' + string_params['CanonicalizedHeaders'] + '\n' // 补充必填换行符 + string_params['CanonicalizedResource']) // 同步修正请求头,添加Content-Type headers : { "x-ms-date" : request_time, "x-ms-version" : api_version, "Content-Length": dataLength, "Content-Type": "text/plain", "x-ms-blob-type": blob_type, "Authorization" : signature }
内容的提问来源于stack exchange,提问作者kira
相关产品推荐
相关产品推荐

