I'm trying to create a single model with a few attributes:
type Guest @model {
id: ID!
name: String
dayGuest: Boolean
attending: Boolean
dietryRequirements: String
owner: String
}
I'd like to adjust how different users can access the data within this model:
Users that are assigned to the 'admins' group within cognito should be able to create, read, update and delete all the fields within a record.
The owner of the record should be able to read every field and update the
attendinganddietryRequirementsfields.- Any user with a valid JWT should be able to update the
ownerfield.
To achieve this I have implemented the following @auth directives:
@auth(rules: [{allow: groups, groups: ["admins"]}])on theGuestmodel@auth(rules: [{allow: owner, ownerField: "owner", operations:[read]}])on theGuestmodel and@auth(rules: [{allow: owner, ownerField: "owner", operations: [update]}])on theattendinganddietryRequirementsfields.@auth(rules: [{allow: private, operations: [update]}])on theownerfield.
The final model looks like this:
type Guest @model @auth(rules: [{allow: groups, groups: ["admins"]}, {allow: owner, ownerField: "owner", operations:[read]}]){
id: ID!
name: String
dayGuest: Boolean
attending: Boolean @auth(rules: [{allow: owner, ownerField: "owner", operations: [update]}])
dietryRequirements: String @auth(rules: [{allow: owner, ownerField: "owner", operations: [update]}])
owner: String @auth(rules: [{allow: private, operations: [update]}])
}
This doesn't seem to work and I can't work out why. The admin user can view everything and create new objects. A validated user (not owner) cannot update the owner field as this returns an unauthorised error. An owner can view all the records regardless of them being the owner of each specific record or not.
How can I achieve what I want?