AWS Lambda Post-Confirmation触发器执行GraphQL mutation遇授权错误
解决AWS Lambda调用AppSync createPlayer mutation的授权错误
问题描述
执行Cognito用户确认触发的AWS Lambda函数时,调用GraphQL的createPlayer mutation遇到授权错误,错误信息如下:
PostConfirmation failed with error GraphQL error: Not Authorized to access createPlayer on type Mutation
相关代码
Lambda函数(Node.js)
const appsync = require("aws-appsync"); const gql = require("graphql-tag"); require("cross-fetch/polyfill"); exports.handler = async (event, context, callback) => { const graphqlClient = new appsync.AWSAppSyncClient({ url: process.env.API_TICTACTOE010147_GRAPHQLAPIENDPOINTOUTPUT, region: process.env.REGION, auth: { type: "AWS_IAM", credentials: { accessKeyId: process.env.AWS_ACCESS_KEY_ID, secretAccessKey: process.env.AWS_SECRET_ACCESS_KEY, sessionToken: process.env.AWS_SESSION_TOKEN, }, }, disableOffline: true, }); const mutation = gql` mutation createPlayer( $name: String! $cognitoID: String! $username: String! $email: AWSEmail! ) { createPlayer( input: { cognitoID: $cognitoID email: $email name: $name username: $username } ) { id } } `; try { await graphqlClient.mutate({ mutation, variables: { name: event.request.userAttributes.name, username: event.userName, cognitoID: event.request.userAttributes.sub, email: event.request.userAttributes.email, }, }); callback(null, event); } catch (error) { callback(error); } };
GraphQL Schema(相关部分)
type Player @model @auth( rules: [ { allow: private, operations: [read] } { allow: owner, ownerField: "username", operations: [update] } { allow: private provider: iam operations: [read, create, update, delete] } ] ) { id: ID! cognitoID: String! username: String! @primaryKey name: String! email: AWSEmail! }
解决方案
1. 修正Lambda的凭证获取方式
Lambda运行时会自动注入执行角色的临时凭证,无需手动从环境变量读取。修改AWSAppSyncClient的初始化代码,使用AWS SDK默认凭证链:
// 顶部新增AWS SDK引入 const AWS = require('aws-sdk'); // 替换原有的client初始化代码 const graphqlClient = new appsync.AWSAppSyncClient({ url: process.env.API_TICTACTOE010147_GRAPHQLAPIENDPOINTOUTPUT, region: process.env.REGION, auth: { type: "AWS_IAM", credentials: AWS.config.credentials // 使用默认凭证链 }, disableOffline: true, });
2. 给Lambda执行角色添加AppSync权限
为Lambda的执行角色附加以下IAM策略,允许调用createPlayer mutation:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "appsync:GraphQL", "Resource": "arn:aws:appsync:<你的AWS区域>:<你的AWS账号ID>:apis/<你的AppSync API ID>/types/Mutation/fields/createPlayer" } ] }
替换占位符为实际的区域、账号ID和AppSync API ID。
3. 确认AppSync启用IAM认证
进入AppSync控制台,找到目标API,在Settings的Authentication providers中,确保AWS IAM已启用。
4. 验证Schema的授权规则
当前Schema中的@auth规则已包含允许IAM执行create操作,无需修改:
{ allow: private provider: iam operations: [read, create, update, delete] }
完成以上步骤后,重新部署Lambda函数和AppSync API,即可解决授权错误。
内容的提问来源于stack exchange,提问作者Muhammad Umair Alim
相关产品推荐
相关产品推荐

