I'm currently having issues deleting an object that a user owns even when I open up all of the permissions. I am able to create the objects just fine but attempting to delete the object results in an error saying "Not Authorized to access deleteJobPost on type Mutation".
Here's my model:
type JobPost
@model
@auth(
rules: [
{ allow: public, operations: [read] }
# { allow: private, operations: [read, create], provider: userPools }
{ allow: owner, operations: [create, read, update, delete] }
]
) {
id: ID!
companyName: String!
positionTitle: String! }
Here's the code that's doing the delete operation:
const deleteJobHandler = useCallback(
async (job: JobPost) => {
console.log(await Auth.currentSession());
try {
await API.graphql(graphqlOperation(deleteJobPost, { input: { id: job.id }}));
} catch (ex: any) {
console.log(ex);
}
},
[jobs]
);
Relevant backend config:
"output": {
"authConfig": {
"defaultAuthentication": {
"authenticationType": "AMAZON_COGNITO_USER_POOLS",
"userPoolConfig": {
"userPoolId": "<redacted>"
}
},
"additionalAuthenticationProviders": [
{
"authenticationType": "API_KEY",
"apiKeyConfig": {
"apiKeyExpirationDays": 7,
"apiKeyExpirationDate": "2022-06-05T16:51:50.439Z",
"description": "app api key"
}
}
]
}
}
I have a valid Cognito session and also see the session token being used as the authorization header within the delete request. I've read many guides that are doing the exact same thing and this should be fairly trivial but i'm not having much success. I have ran amplify codegen model after every backend update so I know my mutation/queries are all up to date. Anyone else run into something similar or see what i'm doing wrong here?
