get user info in context.identity within Lambda function when using icognito identity pool

Viewed 204

I am using lambda post authentication to trigger appsync mutation to store users details in dynamodb. I want to user the user's context.identity.cognitoIdentityId as specified in the docs https://docs.aws.amazon.com/appsync/latest/devguide/resolver-context-reference.html#aws-appsync-resolver-context-reference-identity when using IAM authorization with credentials vended from Amazon Cognito identity pools. however, when I log context in cloud watch, the identity object in cloud watch is missing, thus I am unable to store the user's details in dynamodb.

const env = require('process').env;
const fetch = require('node-fetch');
const AWS = require('aws-sdk');

AWS.config.update({
    region: env.AWS_REGION,
    credentials: new AWS.Credentials(env.AWS_ACCESS_KEY_ID, 
env.AWS_SECRET_ACCESS_KEY, env.AWS_SESSION_TOKEN)
});


module.exports  = {
    postAuthSignup: (event, context, callback) => {

        console.log(`Event = ${JSON.stringify(event, null, 2)}`);
        console.log(`Context = ${JSON.stringify(context, null, 2)}`);
        console.log(`Env = ${JSON.stringify(env, null, 2)}`);

        const Signup = `mutation Signup($input: CreateSignUpInput) {
            signup(input: $input) {
                id
                firstname
                middlename
                lastname
                phone{
                    mobile
                }
                email
            }
        }`;

        const details = {
            input: {
                id: context.identity.cognitoIdentityId,
                firstname: event.request.userAttributes.name,
                lastname: event.request.userAttributes.family_name,
                middlename: event.request.userAttributes.middle_name,
                phone: {
                    mobile: event.request.userAttributes.phone_number
                },
                email: event.request.userAttributes.email
            }
        };

        const post_body = {
            query: Signup,
            operationName: 'Signup',
            variables: details
        };

        console.log(`Posting ${JSON.stringify(post_body, null, 2)}`);

        // post GraphQl mutation to AWS AppSync using signed connection

        const uri = new URL(env.GRAPHQL_API);
        const httpRequest = new AWS.HttpRequest(uri.href, env.REGION);
        httpRequest.headers.host = uri.host;
        httpRequest.headers['Content-Type'] = 'application/json';
        httpRequest.method = 'POST';
        httpRequest.body = JSON.stringify(post_body);

        AWS.config.credentials.get(err => {
            const signer = new AWS.Signers.V4(httpRequest, "appsync", true);
            signer.addAuthorization(AWS.config.credentials, AWS.util.date.getDate());


            const options = {
                method: httpRequest.method,
                body: httpRequest.body,
                headers: httpRequest.headers
            };

            fetch(uri.href, options)
            .then(res => res.json())
            .then(json => {
                console.log(`JSON Response = ${JSON.stringify(json, null, 2)}`);
                callback(null, event);
            })
            .catch(err => {
                console.error(`FETCH ERROR: ${JSON.stringify(err, null, 2)}`);
                callback(err);
            });
        });
    }
};

this is my lambda post authentication function. I would be glad on assistance to get the context.identity from within the lambda function.

0 Answers
Related