通过直接URL访问Azure Blob存储中上传的图片失败问题排查
Hey there! Let's break down what's happening here and walk through the solutions.
First, your hunch is spot-on: Azure Blob Storage defaults to private access for all containers and blobs. That's why copying the raw URI gives you a ResourceNotFound error—without proper authorization, the storage service won't let you access the blob. The URL Storage Explorer uses works because it automatically generates a SAS (Shared Access Signature) token with temporary access permissions appended to the URI.
Here are two main ways to make your blobs accessible via a known URI:
Option 1: Enable Anonymous Public Access for the Container
This makes all blobs in the container publicly accessible without needing a SAS token. Great for static content like images that don't require access control.
Follow these steps in the Azure Portal:
- Navigate to your Storage V2 account
- Go to Blob containers and select your target container
- Click Change access level (found in the container's settings menu)
- Choose one of the public access options:
- Blob (anonymous read access for blobs only): Lets anyone read blobs in the container, but they can't list the container's contents
- Container (anonymous read access for containers and blobs): Lets anyone read blobs and list all items in the container
- Save the setting. Now your raw blob URIs will work directly in the browser.
Note: This makes all content in the container public. Only use this if you don't need to restrict access to individual blobs.
Option 2: Generate a Persistent SAS Token (For Controlled Access)
If you want to keep blobs private but share specific ones with authorized users, generate a SAS token that grants limited access (e.g., read-only, time-bound).
Generate SAS in Code
You can modify your existing upload code to return a SAS-enabled URL:
public async Task<string> UploadFileAndGetSasUrl(string fileName, string targetPath) { var blobRef = Container.GetBlockBlobReference(targetPath); blobRef.Properties.ContentType = GetContentType(fileName); await blobRef.UploadFromFileAsync(fileName); // Define SAS constraints var sasPolicy = new SharedAccessBlobPolicy { SharedAccessStartTime = DateTime.UtcNow.AddMinutes(-5), // Avoid time sync issues SharedAccessExpiryTime = DateTime.UtcNow.AddYears(1), // Set your desired expiration Permissions = SharedAccessBlobPermissions.Read // Grant only read access }; // Generate SAS token and build the full URL string sasToken = blobRef.GetSharedAccessSignature(sasPolicy); return $"{blobRef.Uri}{sasToken}"; }
Generate SAS Manually in Azure Portal
- Find your target blob in the portal
- Click Generate SAS in the blob's overview menu
- Configure permissions (e.g., Read), expiration date, and other constraints
- Click Generate and copy the full SAS URI to use wherever you need it
Quick Checkpoints to Rule Out Other Issues
- Double-check the blob URI: Azure Blob Storage is case-sensitive—make sure container and blob names match exactly what's in your storage account
- Verify storage account firewall settings: If your account has a firewall enabled, only allowed IP addresses can access blobs, even with public access or SAS tokens. Adjust the firewall rules if needed.
内容的提问来源于stack exchange,提问作者Tom Troughton

