【问题标题】:AppSync query returns Unauthorized when using an IAM account使用 IAM 账户时,AppSync 查询返回 Unauthorized
【发布时间】:2021-12-03 17:44:04
【问题描述】:

我正在使用 AWS Amplify。我的 GraphQL 架构中有两个如下模型。

type Class 
  @model 
  @auth(rules: [{ 
    allow: owner, 
    identityClaim: "sub" 
  }      
  {
    allow: owner
    identityClaim: "sub" 
    ownerField: "studentUserIds"
    operations: [read]
  }
  { 
    allow: private, 
    provider: iam 
    operations: [read]
  }
]) {
  id: ID!
  name: String!
  studentUserIds: [String!]
  students: [Student!] @connection(keyName: "ClassStudent", fields: ["id"])
}


type Student
  @model(queries: null)
  @auth(
    rules: [
      { allow: owner, identityClaim: "sub", operations: [create, update, delete, read] }
      { allow: private, provider: iam, operations: [create, update, delete, read] }
      { allow: owner, ownerField: "studentUserId", operations: [update, delete] }
      { allow: private, operations: [read] }
    ]
  )
  @key(name: "ClassStudent", fields: ["classId", "id"]) 
  @key(name: "ClassesByStudent", fields: ["studentUserId"], queryField: "classesByStudent") {
  id: ID!
  classId: ID!
  class: Class @connection(fields: ["classId"])
  studentUserId: ID!
  user: User! @connection(fields: ["studentUserId"])
  owner: String
}

当我使用 IAM 帐户运行 classesByStudent 时,我收到未经授权的响应,即使 IAM 提供程序对 Student 表和 Class 表都有读取权限。我做错了什么?

【问题讨论】:

    标签: aws-amplify aws-appsync


    【解决方案1】:

    我添加以下错误:

    {"errorType":"Unauthorized","message":"Not Authorized to access onCreateMessage on type Message"}
    

    通过创建 amplify/backend/api//custom-roles.json 文件为我解决了这个问题,如 here 所述

    【讨论】:

    • 我通过删除queries: null解决了这个问题。
    • 这显然是一个错误,但根据我的经验,AWS Amplify 有很多这样的错误。
    猜你喜欢
    • 2022-01-21
    • 2018-11-16
    • 2019-01-19
    • 2019-10-10
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多