设置 Azure Blob 服务属性 (REST API) 时出现“身份验证格式不正确”

kaq*_*ues 6 azure-storage

我正在尝试按照以下说明在我的 Azure Blob 存储帐户上设置 CORS 规则。

这是我提出请求后收到的错误:

400 认证信息的格式不正确。检查 Authorization 标头的值

请求网址:

PUT https://[MyAccountName].blob.core.windows.net/?restype=service&comp=properties
Run Code Online (Sandbox Code Playgroud)

请求头:

x-ms-version: 2013-08-15
x-ms-date: Tue, 25 Feb 2014 13:02:00 GMT
Authorization: SharedKey
[MyAccountName]: [MyAccountKey]
Content-Length: 329
Host: [MyAccountName].blob.core.windows.net
Run Code Online (Sandbox Code Playgroud)

请求正文:

<?xml version="1.0" encoding="utf-8"?>
<StorageServiceProperties>
    <Cors>   
          <CorsRule>
                <AllowedOrigins>http://www.example.com</AllowedOrigins>
                <AllowedMethods>GET</AllowedMethods>
                <ExposedHeaders>x-ms-meta-data*,x-ms-meta*</ExposedHeaders>
                <AllowedHeaders>x-ms-meta-target*,x-ms-meta*</AllowedHeaders>
                <MaxAgeInSeconds>200</MaxAgeInSeconds>
        </CorsRule>
    <Cors>
</StorageServiceProperties>
Run Code Online (Sandbox Code Playgroud)

jsg*_*pil 9

对于访问此页面并想知道为什么即使您使用共享访问签名 URL 也会出现此错误的人,那么您很可能将您的 APP 令牌发送到 Azure。在这种情况下,请确保不包含 Authorization 标头。

  • 是的。我从其他东西添加基本的身份验证标头并遇到了这个。 (2认同)

Ser*_*ler 5

该请求具有不完整的授权标头。它需要包含身份验证方案、存储帐户名称和签名。例如;

Authorization: SharedKey myaccount:Z1lTLDwtq5o1UYQluucdsXk6/iB7YxEu0m6VofAEkUE=
Run Code Online (Sandbox Code Playgroud)

有关详细信息,请参阅Windows Azure 存储服务的身份验证。另一方面,如果您使用 Windows Azure 存储客户端库之一,它将为您处理身份验证。对于 .NET 库,请参阅我们的NuGet 包。


loo*_*nix 5

按照@jsgoupil 所说:

对于到达此页面并想知道为什么即使您使用共享访问签名 URL 也会收到此错误的人,那么您很可能正在将您的应用程序令牌发送到 Azure。在这种情况下,请确保不包含授权标头。

如果您有拦截器,您可以按照此 stackOverflow 帖子中的说明向请求添加跳转: https ://stackoverflow.com/a/49047764/5232022

export const InterceptorSkipHeader = 'X-Skip-Interceptor'; // <-- ADD THIS

@Injectable()
export class SkippableInterceptor implements HttpInterceptor {

  intercept(req: HttpRequest<any>, next: HttpHandler): Observable<HttpEvent<any>> {
    // Add the following if to your interceptor
    if (req.headers.has(InterceptorSkipHeader)) {
      const headers = req.headers.delete(InterceptorSkipHeader);
      return next.handle(req.clone({ headers }));
    }

    ...  // intercept
  }

}
Run Code Online (Sandbox Code Playgroud)

然后每当你想跳过特定请求的拦截时:

const headers = new HttpHeaders().set(InterceptorSkipHeader, ''); // <-- this will skip it

this.httpClient.get<ResponseType>(someUrl, { headers }) // <-- dont forget to add it here as well
Run Code Online (Sandbox Code Playgroud)