we're developing an AWS AppSync API and want to use a custom lambda resolver.
We created a simple lambda function for testing purposes (Reference: https://aws.amazon.com/de/blogs/mobile/appsync-lambda-auth/):
// This is sample code. Please update this to suite your schema
exports.handler = async (event) => {
console.log(`event >`, JSON.stringify(event, null, 2));
const {
authorizationToken,
requestContext: { apiId, accountId },
} = event;
const response = {
isAuthorized: authorizationToken === 'custom-authorized',
resolverContext: {
userid: 'user-id',
info: 'contextual information A',
more_info: 'contextual information B',
},
deniedFields: [
// `arn:aws:appsync:${process.env.AWS_REGION}:${accountId}:apis/${apiId}/types/Event/fields/comments`,
// `Mutation.createEvent`,
],
ttlOverride: 300,
};
console.log(`response >`, JSON.stringify(response, null, 2));
return response;
};
... configured lambda as the API's authorization mode:
xxx % amplify update api
? Select from one of the below mentioned services: GraphQL
General information
- Name: drivebuddy
- API endpoint: https://xxxx.appsync-api.eu-central-1.amazonaws.com/graphql
Authorization modes
- Default: Lambda
Conflict detection (required for DataStore)
- Disabled
? Select a setting to edit Authorization modes
? Choose the default authorization type for the API Lambda
? Choose a Lambda authorization function Use a Lambda function already added in the current Amplify project
? Choose one of the Lambda functions graphQlLambdaAuthorizer516a27b2
? How long should the authorization response be cached in seconds? 300
? Configure additional auth types? No
GraphQL schema compiled successfully.
... and created a type with custom auth rule:
type DrivingRecord @model @auth(rules: [{ allow: custom }]) {
id: ID!
userID: ID
vehicle: String!
dateTime: AWSDateTime
}
After amplify push we can query the API without any problem:
curl -XPOST -H "Content-Type:application/graphql" -H "Authorization:custom-authorized" -d '{"query": "query { listDrivingRecords { items { id } } }"}' https://xxxxx.appsync-api.eu-central-1.amazonaws.com/graphql
Response:
"data":{"listDrivingRecords":{"items":[{"id":"9686ac34-f4c9-4ca3-91ae-af4ee00a75c3"}]}}}
But locally (amplify mock) we get the following error
curl -XPOST -H "Content-Type:application/graphql" -H "Authorization:custom-authorized" -d '{"query": "query { listDrivingRecords { items { id } } }"}' http://192.168.0.133:20002/graphql
Response:
{"errors":[{"errorType":"UnauthorizedException","message":"UnauthorizedException: Invalid JWT token"}]}
Does amplify mock support lambda resolvers for AppSync?
Is there a workaround for local development?
BR Stefan