【问题标题】:Why isn't my Azure SAS Token Signature matching?为什么我的 Azure SAS 令牌签名不匹配?
【发布时间】:2017-08-17 21:35:19
【问题描述】:

这是我尝试访问存储中的 blob 时返回的错误:

代码:身份验证失败 消息:服务器无法验证请求。确保 Authorization 标头的值正确形成,包括签名。 AuthenticationErrorDetail:签名不匹配。使用的签名字符串是 xxstorageaccount rwdlac b sco 2017-08-17T21:29:24Z 2017-08-17T21:34:24Z https 2017-04-17

这是我的代码:

$storageAccount = config('azure.storage.account');

$start = new \DateTime();     
$end = (new \DateTime())->modify('+5 minutes');
$start = $start->format('Y-m-d\TH:i:s\Z');
$end = $end->format('Y-m-d\TH:i:s\Z');

$toSign = $storageAccount . "\n";
$toSign .= "rwdlac" . "\n";
$toSign .= "b" . "\n";
$toSign .= "sco" . "\n";
$toSign .= $start . "\n";
$toSign .= $end . "\n"; 
$toSign .= "\n";
$toSign .= "https" . "\n";
$toSign .= "2017-04-17" . "\n";

$signature = rawurlencode(base64_encode(hash_hmac('sha256', $toSign, $sasKeyValue, TRUE))); 
$token = "?sv=2017-04-17&ss=b&srt=sco&sp=rwdlac&se=" . $end . "&st=" . $start . "&spr=https&sig=" . $signature;

return $uri . $token;

【问题讨论】:

  • $sasKeyValue 变量的值是多少?是帐号密钥吗?

标签: php azure token


【解决方案1】:

你可以做两件事来避免这个错误。

  1. 通过setTimezone() 函数将开始结束时间转换为格林威治标准时间,或者考虑改用gmdate function

  2. 通过base64_decode()函数解码base64账号密钥。

请将您的代码更改如下:

$storageAccount = config('azure.storage.account');

$start = (new \DateTime())->setTimezone(new DateTimeZone('GMT'));     
$end = (new \DateTime())->setTimezone(new DateTimeZone('GMT'))->modify('+5 minutes');
$start = $start->format('Y-m-d\TH:i:s\Z');
$end = $end->format('Y-m-d\TH:i:s\Z');

$toSign = $storageAccount . "\n";
$toSign .= "rwdlac" . "\n";
$toSign .= "b" . "\n";
$toSign .= "sco" . "\n";
$toSign .= $start . "\n";
$toSign .= $end . "\n"; 
$toSign .= "\n";
$toSign .= "https" . "\n";
$toSign .= "2017-04-17" . "\n";

$signature = rawurlencode(base64_encode(hash_hmac('sha256', $toSign, base64_decode($sasKeyValue), TRUE))); 
$token = "?sv=2017-04-17&ss=b&srt=sco&sp=rwdlac&se=" . $end . "&st=" . $start . "&spr=https&sig=" . $signature;

return $uri . $token;

【讨论】:

    猜你喜欢
    • 2020-05-29
    • 2017-04-23
    • 2019-12-04
    • 2022-01-11
    • 1970-01-01
    • 2021-04-17
    • 2015-03-26
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多