Generate SAS token to manage Azure Blob Container using PowerShell REST API

Viewed 931

I'm downloading files from Azure Blob Storage with PowerShell REST API. The code works perfectly, the only think is that I have to hardcode the SAS. Instead of hardcoding the SAS I want to generate the SAS token programmatically in PowerShell REST API. This is the reference of the code I'm using https://rzander.azurewebsites.net/download-files-from-azure-blob-storage-with-powershell/

I searched lot of documentation on Microsoft Doc, I found one for Azure Event Hub https://docs.microsoft.com/en-us/rest/api/eventhub/generate-sas-token#powershell

I am looking for some thing similar to this which can generate the SAS for Azure Storage Account, Azure Blob Container but it should be the in PowerShell REST API.

Note: I cannot use Az cmdlet module New-AzStorageAccountSASToken because I am implementing this in Azure Function App Trigger, and I need to use simple REST API in PowerShell.


Update: I tried to use the documentation to generate the SAS Token. Below is the PowerShell REST API code:

Function Get-MyBlob{
        $StorageAccountName = "MYSTORAGEACCOUNT"
        $StorageContainerName = "MYCONTAINER"
        $StorageAccountKey = "MYSTORAGEACCOUNTACCESSKEY"
        $blobItem = "coloured-paper.jpg"
        $Url = "https://$StorageAccountName.blob.core.windows.net/$StorageContainerName/$blobItem"

        $signedPermissions = "rw"
        $signedStart = "2021-10-03"
        $signedExpiry = "2021-10-13"
        $canonicalizedResource = "/$StorageAccountName/$StorageContainerName/$blobItem"
        $signedVersion = "2012-02-12"

        $StringToSign = $signedpermissions + "\n" +  
               $signedstart + "\n" +  
               $signedexpiry + "\n" +  
               $canonicalizedresource + "\n" +
               $signedVersion + "\n"
        

        $sharedKey = [System.Convert]::FromBase64String($StorageAccountKey)

        $hasher = New-Object System.Security.Cryptography.HMACSHA256
        $hasher.Key = $sharedKey              
        $signedSignature = [System.Convert]::ToBase64String($hasher.ComputeHash([System.Text.Encoding]::UTF8.GetBytes($StringToSign)))

        $method = "GET"
        $headerDate = '2012-02-12'
        $headers = @{"x-ms-version" = "$headerDate" }
        $xmsdate = (get-date -format r).ToString()
        $headers.Add("x-ms-date", $xmsdate)
        
        $headers.Add("Authorization", "SharedKey " + $StorageAccountName + ":" + $signedSignature);
        write-host -fore green $signatureString
        Invoke-RestMethod -Uri $Url -Method $method -headers $headers
    }

But when I invoke this, I get following error:

Error Details: AuthenticationFailedServer failed to authenticate the request. Make sure 
the value of Authorization header is formed correctly including the signature.
RequestId:47e97e15-601e-0068-202d-b9caad000000
Time:2021-10-04T14:40:11.3025359ZThe MAC signature found in the HTTP request 'JQ54my0pZGv+XpcaMMiVjXOXV/e0ATU1TrWewgqU4Gs=' is not the same as any computed signature. Server used following string to sign: 'GET
0
x-ms-date:Mon, 04 Oct 2021 20:10:09 GMT
x-ms-version:2012-02-12
/mkatestscriptstorage/usl-customer-package/coloured-paper.jpg'.

Can anyone help what error am I making. Is the StringToSign valid?

0 Answers
Related