C#访问跨机器共享文件夹CSV时遇Not allowed to load local resource错误求助
The error you're hitting is a standard security restriction in web-based environments (like the framework powering your card system—probably Microsoft Teams or Bot Framework). Browsers and web clients block file:// URLs because they can't access local or network-shared resources directly from a web context—it's a safeguard against unauthorized file access.
Here are two reliable solutions to get around this:
1. Host the CSV on a Web Server
The simplest fix is to serve your CSV file via HTTP/HTTPS instead of using a network share path. You can:
- Upload the file to a web server (IIS, Apache, Nginx, etc.) on your network
- Use a cloud storage service with a public or signed URL
- Then update your card's
valueto point to the HTTP URL instead of thefile://path.
Modified code example:
var Card = new Card { Text = "Click here to view report", Buttons = new List<CardAction> { new CardAction(ActionTypes.DownloadFile, "Get-Report", value: @"https://your-web-server-url/new/test.csv") } }; return Card.ToAttachment();
2. Proxy the File Through Your Backend
If you can't host the CSV externally, you can create an endpoint in your backend application that reads the file from the network share and streams it to the user as a download. This works because backend servers can access network shares (if they have the right permissions) without the browser's security restrictions.
Step 1: Update the Card to Point to Your Backend Endpoint
var Card = new Card { Text = "Click here to view report", Buttons = new List<CardAction> { new CardAction(ActionTypes.OpenUrl, "Get-Report", value: @"https://your-backend-domain/api/download-report") } }; return Card.ToAttachment();
Step 2: Create the Backend Endpoint (Example in ASP.NET Core)
This endpoint will read the CSV from the network share and return it as a downloadable file:
[HttpGet("api/download-report")] public IActionResult DownloadReport() { // Use UNC path for network shares (\\machinename\share\file) var networkFilePath = @"\\machinename\new\test.csv"; if (!System.IO.File.Exists(networkFilePath)) { return NotFound("Report file not found."); } // Read the file content var fileContent = System.IO.File.ReadAllBytes(networkFilePath); // Return as downloadable CSV return File( fileContent, "text/csv", "test.csv" // Name users will see when downloading ); }
Important Permission Note
Make sure the service account running your backend application has read access to the network share (\\machinename\new). If you're using IIS, check the app pool identity; if it's a console app, run it under an account with access to the share.
Why file:// Doesn't Work
Web browsers operate in a security sandbox that prevents them from accessing local or network resources directly via file:// URLs. This is to stop malicious websites from accessing files on your machine or network without permission. Even if the share is accessible on your local network, the browser can't reach it through that protocol.
内容的提问来源于stack exchange,提问作者shivani joshi

