I am building an app using Ionic, Capacitor and AWS Amplify. I am having some issues
I have set up federated sign-in for my app using the capacitor plugin https://github.com/capacitor-community/facebook-login and call Auth.federatedSignIn() as per the below. This logs my user in with a federated identity. This is great, but it means I cannot use @auth(rules: [{ allow: owner }]) in my graphql schema. Is there any way to create a user in the userpool when calling Auth.federatedSignIn()? I know that calling Auth.federatedSignIn({ provider: "Facebook" }) and using the hosted UI works like this, but I do not want to redirect my user to a browser/chrome tab to sign in. I would like the authentication to be provided by the native functionality provided by the above capacitor plugin.
Using the federated identity allows me to restrict access to my graphql schema using IAM: @auth(rules: [{ allow: private, provider: iam }]) but this is limited to private and public rules. I want to limit the graphql api so that users can see only their own entries with functionality like @auth(rules: [{ allow: owner }]).
Maybe I am going about this the wrong way? I'm stumped. Any help is appreciated. Thanks.
const FBLogIn = async () => {
const result = await FacebookLogin.login({ permissions: FACEBOOK_PERMISSIONS });
const { email } = await FacebookLogin.getProfile({ fields: ['email'] });
try {
const userDetails = await Auth.federatedSignIn("facebook", { token: result.accessToken.token, expires_at: result.accessToken.expires }, { name: result.accessToken.userId, email: email })
} catch (error) {
console.log(error)
}
}