You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Python Azure SDK在同Blob容器内复制文件时遭遇ClientAuthenticationError认证错误求助

使用Python Azure SDK在同Blob容器内复制文件时遭遇ClientAuthenticationError认证错误求助

看起来你在使用Azure Python SDK复制同容器内的Blob时碰到了认证卡壳的问题,错误提示里的CannotVerifyCopySource是核心线索,我来帮你梳理几个大概率能解决问题的方向:

首先明确你的问题场景和代码:

我正在使用Python版azure-sdk在同一个容器内复制Blob,但遇到了认证错误。

我的源代码如下:

import time
from azure.storage.blob import BlobServiceClient

status = None

blob_service_client = BlobServiceClient.from_connection_string(storage_account_connection_string)

copied_blob = blob_service_client.get_blob_client(containerName, 'test.csv')

result = copied_blob.start_copy_from_url(source_url=source_blob, requires_sync=True)

print(result)

status = result['copy_status']

if status != "success":
    for i in range(1000):
        props = copied_blob.get_blob_properties()
        status = props.copy.status
        print("Copy status: " + status)
        if status == "success":
            # copy finished
            break
        time.sleep(60*0.5)

收到的错误信息:

ClientAuthenticationError: Server failed to authenticate the request. Please refer to the information in the www-authenticate header.
Time:2024-01-10T14:36:11.9520689Z
ErrorCode:CannotVerifyCopySource
Content: CannotVerifyCopySourceServer failed to authenticate the request. Please refer to the information in the www-authenticate header.
Time:2024-01-10T14:36:11.9520689Z

可能的解决方法:

  • 确保源Blob的URL是经过授权的
    即使在同一个容器内,start_copy_from_url要求传入的source_url必须是Azure存储服务能验证权限的合法URL。如果直接传Blob名称或者未签名的URL,就会触发认证错误。正确做法是生成带SAS签名的源Blob URL:

    from datetime import datetime, timedelta
    
    # 获取源Blob的客户端
    source_blob_client = blob_service_client.get_blob_client(containerName, "你的源Blob名称")
    # 生成SAS令牌,至少需要读权限("r"),设置合适的过期时间
    sas_token = source_blob_client.generate_sas(
        permission="r",
        expiry=datetime.utcnow() + timedelta(hours=1)  # 1小时后过期,可按需调整
    )
    # 组合成完整的授权URL
    source_url = f"{source_blob_client.url}?{sas_token}"
    
    # 之后用这个source_url调用start_copy_from_url
    result = copied_blob.start_copy_from_url(source_url=source_url, requires_sync=True)
    
  • 检查存储账户连接字符串的权限
    确认你使用的storage_account_connection_string对应的身份(比如账户密钥或托管标识)拥有足够权限:至少需要读取源Blob、写入目标Blob的权限。可以登录Azure门户,在存储账户的「IAM」选项里检查角色分配,比如分配「Blob数据参与者」角色。

  • 排查代码变量的正确性

    • 确认containerName变量的拼写和实际容器名称完全一致,大小写也要注意;
    • 检查source_blob变量类型:start_copy_from_url的source_url参数必须是字符串格式的URL,误传Blob客户端对象或其他类型会导致验证失败。

备注:内容来源于stack exchange,提问作者Amir Hossein Eyvazkhani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.20 08:38:09