{"record":{"id":"2baa9958bc0dde46","repo":"hashicorp/terraform","slug":"new-shared-key-authorizer-v","errorCode":null,"errorMessage":"new shared key authorizer: %v","messagePattern":"new shared key authorizer: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/azure/api_client.go","lineNumber":169,"sourceCode":"\tswitch {\n\tcase c.sasToken != \"\":\n\t\tlog.Printf(\"[DEBUG] Building the Blob Client from a SAS Token\")\n\t\tc.configureClient(blobsClient.Client, nil)\n\t\tblobsClient.Client.AppendRequestMiddleware(func(r *http.Request) (*http.Request, error) {\n\t\t\tif r.URL.RawQuery == \"\" {\n\t\t\t\tr.URL.RawQuery = c.sasToken\n\t\t\t} else if !strings.Contains(r.URL.RawQuery, c.sasToken) {\n\t\t\t\tr.URL.RawQuery = fmt.Sprintf(\"%s&%s\", r.URL.RawQuery, c.sasToken)\n\t\t\t}\n\t\t\treturn r, nil\n\t\t})\n\t\treturn blobsClient, nil\n\n\tcase c.accessKey != \"\":\n\t\tlog.Printf(\"[DEBUG] Building the Blob Client from an Access Key\")\n\t\tauthorizer, err := auth.NewSharedKeyAuthorizer(c.storageAccountName, c.accessKey, auth.SharedKey)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"new shared key authorizer: %v\", err)\n\t\t}\n\t\tc.configureClient(blobsClient.Client, authorizer)\n\t\treturn blobsClient, nil\n\n\tcase c.azureAdStorageAuth != nil:\n\t\tlog.Printf(\"[DEBUG] Building the Blob Client from AAD auth\")\n\t\tc.configureClient(blobsClient.Client, c.azureAdStorageAuth)\n\t\treturn blobsClient, nil\n\n\tdefault:\n\t\t// Neither shared access key, sas token, or AAD Auth were specified so we have to call the management plane API to get the key.\n\t\tlog.Printf(\"[DEBUG] Building the Blob Client from an Access Key (key is listed using client credentials)\")\n\t\tkey, err := c.accountDetail.AccountKey(ctx, c.storageAccountsClient)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"retrieving key for Storage Account %q: %s\", c.storageAccountName, err)\n\t\t}\n\t\tauthorizer, err := auth.NewSharedKeyAuthorizer(c.storageAccountName, *key, auth.SharedKey)\n\t\tif err != nil {","sourceCodeStart":151,"sourceCodeEnd":187,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/azure/api_client.go#L151-L187","documentation":"Thrown by getBlobClient on the c.accessKey != \"\" branch when auth.NewSharedKeyAuthorizer(storageAccountName, accessKey, auth.SharedKey) returns an error. The shared-key authorizer base64-decodes the key and prepares HMAC-SHA256 signing; failure means the key value is malformed or the account name is unusable for signing.","triggerScenarios":"access_key is set in the backend config; the value cannot be base64-decoded (extra whitespace, JSON quotes, wrong field pasted, truncated), or storage_account_name is empty/contains characters that break the canonical string-to-sign.","commonSituations":"Operator copy-pasted the key from the portal with leading/trailing whitespace or surrounding quotes; pasted the key ID/name (e.g. key1) instead of the key value; environment variable interpolation produced an empty string; key truncated during transfer.","solutions":["Re-fetch the key via `az storage account keys list -g <rg> -n <acct>` and paste the value verbatim.","Trim any whitespace or surrounding quotes around access_key in the backend block / env var.","Confirm storage_account_name is set and matches the key.","Switch to use_azuread_auth = true to bypass shared-key signing entirely."],"exampleFix":"// before\naccess_key = \"  <pastewith newlines>  \"\n// after\naccess_key = \"<base64-value-with-no-whitespace>\"","handlingStrategy":"validation","validationCode":"// Validate the access key is well-formed base64 before passing to NewSharedKeyAuthorizer.\nfunc validateAccessKey(account, key string) error {\n    if account == \"\" { return fmt.Errorf(\"storage_account_name is empty\") }\n    k := strings.TrimSpace(key)\n    if k == \"\" { return fmt.Errorf(\"access_key is empty after trimming whitespace\") }\n    if _, err := base64.StdEncoding.DecodeString(k); err != nil {\n        return fmt.Errorf(\"access_key is not valid base64: %w\", err)\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always TrimSpace access_key and storage_account_name when reading from env/config.","Fetch keys via `az storage account keys list` and pipe through pbcopy/xclip rather than copy-paste to avoid whitespace.","Prefer use_azuread_auth over shared-key auth in CI."],"tags":["azure","authentication","shared-key","storage-account","credentials"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}