AWS AppSync amplify mock lambda resolver "Invalid JWT token"

Viewed 215

we're developing an AWS AppSync API and want to use a custom lambda resolver.

We created a simple lambda function for testing purposes (Reference: https://aws.amazon.com/de/blogs/mobile/appsync-lambda-auth/):

// This is sample code. Please update this to suite your schema

exports.handler = async (event) => {
  console.log(`event >`, JSON.stringify(event, null, 2));
  const {
    authorizationToken,
    requestContext: { apiId, accountId },
  } = event;
  const response = {
    isAuthorized: authorizationToken === 'custom-authorized',
    resolverContext: {
      userid: 'user-id',
      info: 'contextual information A',
      more_info: 'contextual information B',
    },
    deniedFields: [
      // `arn:aws:appsync:${process.env.AWS_REGION}:${accountId}:apis/${apiId}/types/Event/fields/comments`,
      // `Mutation.createEvent`,
    ],
    ttlOverride: 300,
  };
  console.log(`response >`, JSON.stringify(response, null, 2));
  return response;
};

... configured lambda as the API's authorization mode:

xxx % amplify update api
? Select from one of the below mentioned services: GraphQL

General information
- Name: drivebuddy
- API endpoint: https://xxxx.appsync-api.eu-central-1.amazonaws.com/graphql

Authorization modes
- Default: Lambda

Conflict detection (required for DataStore)
- Disabled

? Select a setting to edit Authorization modes
? Choose the default authorization type for the API Lambda
? Choose a Lambda authorization function Use a Lambda function already added in the current Amplify project
? Choose one of the Lambda functions graphQlLambdaAuthorizer516a27b2
? How long should the authorization response be cached in seconds? 300
? Configure additional auth types? No
GraphQL schema compiled successfully.

... and created a type with custom auth rule:

type DrivingRecord @model @auth(rules: [{ allow: custom }]) {
      id: ID!
      userID: ID
      vehicle: String!
      dateTime: AWSDateTime
    }

After amplify push we can query the API without any problem:

curl -XPOST -H "Content-Type:application/graphql" -H "Authorization:custom-authorized" -d '{"query": "query { listDrivingRecords { items { id } } }"}' https://xxxxx.appsync-api.eu-central-1.amazonaws.com/graphql

Response:

"data":{"listDrivingRecords":{"items":[{"id":"9686ac34-f4c9-4ca3-91ae-af4ee00a75c3"}]}}}

But locally (amplify mock) we get the following error

curl -XPOST -H "Content-Type:application/graphql" -H "Authorization:custom-authorized" -d '{"query": "query { listDrivingRecords { items { id } } }"}' http://192.168.0.133:20002/graphql

Response:

{"errors":[{"errorType":"UnauthorizedException","message":"UnauthorizedException: Invalid JWT token"}]}

Does amplify mock support lambda resolvers for AppSync?

Is there a workaround for local development?

BR Stefan

0 Answers
Related