Skip to content

{Storage} Fix Issues 32284 az storage blob sync using --sas-token - #34174

Open
JiaSeng-v wants to merge 1 commit into
Azure:devfrom
JiaSeng-v:fix/issues_32284
Open

JiaSeng-v wants to merge 1 commit into
Azure:devfrom
JiaSeng-v:fix/issues_32284

Conversation

@JiaSeng-v

@JiaSeng-v JiaSeng-v commented Oct 6, 2026 •

Copy link
Copy Markdown

Related command
az storage blob sync

Description
Fix #32284 az storage blob sync: Fix using azcopy with --sas-token without logging into azcli

When --sas-token is used, the storage SDK leaves client.credential as None and appends the SAS directly to the client URL's query string instead of keeping it as a string credential. client_auth_for_azcopy only checked client.credential, so it always fell back to AAD auth and failed with Please run 'az login' to setup account. (regression related to #32048, which only fixed the --account-key case).

Fix: when credential is empty, also check the client URL's query string for SAS indicators (sig=, sv=, sr=, se=, sp=) before falling back to oauth.

Testing Guide

az storage blob sync -c --account-name --sas-token "" -s --destination

Should sync without prompting for az login.

History Notes

[Storage] Fix #32284: az storage blob sync: Fix using azcopy with --sas-token without login into azcli


This checklist is used to make sure that common guidelines for a pull request are followed.

@JiaSeng-v
JiaSeng-v requested a review from a team as a code owner October 6, 2026 05:57
Copilot AI balanced review requested due to automatic review settings October 6, 2026 05:57
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The narrow fallback addresses the reported failure; the remaining test-coverage suggestion is non-blocking.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Fixes #32284 by allowing az storage blob sync to recognize URL-based SAS authentication without requiring Azure CLI login.

Changes:

  • Checks the client URL for SAS indicators when credentials are absent.
  • Preserves existing account-key handling and OAuth fallback.
File Description
src/​azure-cli/​azure/​cli/​command_modules/​storage/​azcopy/​util.py Recognizes SAS authentication in the client URL query.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +167 to +170
elif getattr(client, "url", None):
query = urlparse(client.url).query
if any(indicator in query for indicator in sas_indicators):
is_oauth = False
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

@JiaSeng-v JiaSeng-v changed the title Fix Issues 32284: az storage blob sync using --sas-token {Storage} Fix Issues 32284 az storage blob sync using --sas-token Oct 6, 2026
@yonzhan Yong Zhang (yonzhan) added this to the Backlog milestone Oct 6, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

az storage blob sync requires 'az login' when using --sas-token

5 participants