GraphQL connections Not Authorized to access in Mutation

Viewed 174

I'm not sure if I'm doing this correctly with the connections in AppSync GraphQL.

This is what my graphql models look like:

type User @model @auth(rules: [{ allow: owner, ownerField: "username" }]) {
  id: ID!
  username: String!
  email: String!
  userType: UserType
}

enum UserType {
  TEACHER
  CREATOR
}

type Teacher @model {
  id: ID!
  userId: ID
  name: String!
  activations: [Activation]
    @connection(keyName: "activationsByTeacherId", fields: ["id"])
  creators: [TeacherCreatorPartnership]
    @connection(name: "TeacherCreatorPartnership")
}

type Creator @model {
  id: ID!
  userId: ID
  name: String!
  email: String!
  username: String
  teachers: [TeacherCreatorPartnership] @connection(name: "CreatorTeacherPartnership")
  posts: [Post] @connection(name: "CreatorPosts")
  activations: [CreatorActivations] @connection(name: "CreatorActivations")
}

type TeacherCreatorPartnership @model(queries: null) {
  id: ID!
  teacher: Teacher! @connection(name: "TeacherCreatorPartnership")
  creator: Creator! @connection(name: "CreatorTeacherPartnership")
}

type CreatorActivations @model(queries: null) {
  id: ID!
  creator: Creator! @connection(name: "CreatorActivations")
  activation: Activation! @connection(name: "ActivationCreators")
}

type Activation
  @model
  @key(
    name: "activationsByTeacherId"
    fields: ["teacherId"]
    queryField: "activationsByTeacherId"
  )
  @auth(
    rules: [
      { allow: groups, groups: ["Admin"] }
      {
        allow: owner
        ownerField: "teacherId"
        operations: [create, update, delete]
      }
      { allow: private, operations: [read] }
      { allow: public, operations: [read] }
    ]
  ) {
  id: ID!
  teacherId: ID!
  title: String!
  teacher: Teacher @connection(fields: ["teacherId"])
  creators: [CreatorActivations] @connection(name: "ActivationCreators")
}

The idea is that when user signs in with Amplify, they'll go through an onboarding process and choose whether they're a creator or a teacher.

This works fine, but the problem is if a signed-in user wants to create a new Activation.

I'm not sure if the graphql on the Activation model is set correctly, perhaps the auth key is wrong?

This is how I'm processing create

const createNewActivation = async () => {
  if (!title || !content || !location) return;
  const newId = uuid();
  activation.id = newId;
  const user = await Auth.currentAuthenticatedUser();
  try {
    await API.graphql({
      query: createActivation,
      variables: {
        input: {
          ...activation,
          teacherId: user.attributes.sub,
        },
      },
      authMode: "AMAZON_COGNITO_USER_POOLS",
    });
  } catch (error) {
    console.log("Error: problem creating activation: ", error);
  }
};

I've also set up a lambda function so that when user confirms their account from sign up, it will save the user information in DynamoDB with an ID, the username, and email.


Edit: Got it working but...

So, I was able to save the data, but I had to change the schema in my Activation model from:

{
  allow: owner
  ownerField: "teacherId"
  operations: [create, update, delete]
}

to just

{
  allow: owner
}

Not sure why I can't set the owner to teacherId? Wouldn't I need this so I can make proper connections to Teacher's model with teachId field?

0 Answers
Related