How to check roles or permissions on AWS AppSync OIDC directive at the Graphql schema level

Viewed 596

I am in the process of transitioning from Cognito to Auth0. For some of my AppSync queries and mutations, I have applied the @aws_auth directive, which can include a list of Cognito groups to control the level of access.

The example below displays a mutation, called createEvent, which only allows users who are in the Cognito groups, tracker_admin and pilot_admin, to execute this mutation.

Here is an example:

createEvent(input: CreateEventInput!): Event
    @aws_auth(cognito_groups:["tracker_admin", "pilot_admin"])

I have successfully configured an additional authentication provider (OPENID_CONNECT) with Auth0 and added the directive @aws_oidc to my GraphQL schema. In my Auth0 dashboard I have set up scopes which get added to the user's access token based on their roles when they authenticate with my application client.

My goal is to update my schema to use the OIDC authentication and to apply permissions to the directive like so:

directive @aws_oidc(
    permissions: [String]
) on OBJECT | FIELD_DEFINITION

createEvent(input: CreateEventInput!): Event
    @aws_oidc(permissions:["create:event"])

My Auth0 access_token does have a "permissions" field which includes a list of the scopes that the user has. These list of permissions come into my lambda resolver in the event context in the "identity" under the "claims".

How can I accomplish this authorization at the schema level with a directive for @aws_oidc just like I currently have with the @aws_auth for User Pool Cognito Groups?

1 Answers

This is way late, but for anyone else who needs help setting up AppSync with OIDC, I came up with this after looking at this blog: https://aws.amazon.com/blogs/mobile/graphql-security-appsync-amplify/ . Below is a sample of how to set this up in your schema.graphql

Change the value of groups to be w/e you need, and groupClaim to be the claim on your OIDC token to read. Tailor the operations as needed

type Foo
  @model
  @auth(
    rules: [
      {
        allow: groups
        groups: ["ADMIN", "USER"]
        operations: [create, update, delete, read]
        provider: oidc
        groupClaim: "role"
      }
    ]
  ) {
  id: ID!
  anotherId: ID!
}
Related