AWS AppSync订阅无法响应外部Lambda更新DynamoDB的问题及权限报错求助
AWS AppSync订阅无法响应外部Lambda更新DynamoDB的问题及权限报错求助
我现在碰到两个棘手的问题,想请教各位大佬帮忙解惑:
问题1:外部Lambda直接更新DynamoDB时,AppSync订阅不触发
我用Python写了Lambda代码,用来更新Amplify SAM模板创建的DynamoDB表。前端通过AppSync的OnUpdateSumitPaymentListener订阅了数据更新事件,但只有通过Amplify应用本身修改数据时,订阅才会正常触发并通知前端;一旦用外部Lambda直接修改DynamoDB数据,前端完全收不到更新通知。
我尝试过参考官方的实时通知相关文档,但里面提到的**无数据源解析器(None data source)**我完全搞不懂怎么配置,而且我是用SAM CLI开发的,不敢随便在控制台改配置,怕后续部署时会被覆盖。更气人的是,文档最后只演示了本来就正常的场景,等于没解决我的实际问题...
问题2:Lambda调用AppSync GraphQL接口时的权限报错
后来我换了个思路,打算让Lambda直接调用AppSync的GraphQL接口来更新数据(想着这样应该能触发订阅?),但调用listBillings查询时一直返回未授权错误:
{ "data": { "listBillings": null }, "errors": [ { "path": [ "listBillings" ], "data": null, "errorType": "Unauthorized", "errorInfo": null, "locations": [ { "line": 2, "column": 3, "sourceName": null } ], "message": "Not Authorized to access listBillings on type ModelBillingConnection" } ] }
我已经给Lambda的IAM角色分配了所有AppSync权限,甚至自定义了一个全量允许的策略:
{ "Version": "2012-10-17", "Statement": [ { "Sid": "VisualEditor0", "Effect": "Allow", "Action": "appsync:*", "Resource": "*" } ] }
但还是没用...
相关代码片段
前端订阅代码
/* subscribe to update */ this.subscription = this.api .OnUpdateSumitPaymentListener() .subscribe((event: any) => { this.getTokenAndCalc(); });
GraphQL Schema
type SumitPayment @model @searchable @auth(rules: [ { allow: owner } { allow: groups, groups: ["admin"] } ]) { id: ID! status: String OGCustomerID: String OGPaymentID: String OGPaymentType: String OGDocumentNumber: String subscriptionPrice: Float owner: String documentDownloadURL: String }
Lambda直接更新DynamoDB的代码
dynamo = boto3.resource('dynamodb') dbTable = dynamo.Table(tableName) keys = {'id': id} dbTable.update_item( Key=keys, UpdateExpression="SET #key = :val", ExpressionAttributeValues={ ':val': value, }, ExpressionAttributeNames={ "#key": key } )
AppSync的Pipeline解析器代码
/** * These are available AWS AppSync utilities that you can use in your request and response handler. * For more information about the utilities that are currently implemented, see * https://docs.aws.amazon.com/en_us/appsync/latest/devguide/resolver-reference-overview-js.html#utility-resolvers. */ import {util} from '@aws-appsync/utils'; /** * This function is invoked before the request handler of the first AppSync function in the pipeline. * The resolver request handler allows you to perform some preparation logic * before executing the defined functions in your pipeline. * @param ctx - Contextual information for your resolver invocation */ export function request(ctx) { return {}; } /** * Pipeline functions exhibit the following behaviors: * 1) Between your request and response handler, the functions of your pipeline resolver will run in sequence. * 2) The resolver's request handler result is made available to the first function as ctx.prev.result. * 3) Each function's response handler result is available to the next function as ctx.prev.result. */ /** * This function is invoked after the response handler of the last AppSync function in the pipeline. * The resolver response handler allows you to perform some final evaluation logic * from the output of the last function to the expected GraphQL field type. * @param ctx - Contextual information for your resolver invocation. */ export function response(ctx) { return ctx.prev.result; }
有没有大佬能指点下,到底该怎么让外部Lambda的更新触发AppSync的订阅,还有这个权限报错到底哪里出问题了?
备注:内容来源于stack exchange,提问作者Elia Weiss
相关产品推荐
相关产品推荐

