You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Lambda Post-Confirmation触发器执行GraphQL mutation遇授权错误

解决AWS Lambda调用AppSync createPlayer mutation的授权错误

问题描述

执行Cognito用户确认触发的AWS Lambda函数时,调用GraphQL的createPlayer mutation遇到授权错误,错误信息如下:

PostConfirmation failed with error GraphQL error: Not Authorized to access createPlayer on type Mutation

相关代码

Lambda函数(Node.js)

const appsync = require("aws-appsync");
const gql = require("graphql-tag");
require("cross-fetch/polyfill");

exports.handler = async (event, context, callback) => {
  const graphqlClient = new appsync.AWSAppSyncClient({
    url: process.env.API_TICTACTOE010147_GRAPHQLAPIENDPOINTOUTPUT,
    region: process.env.REGION,
    auth: {
      type: "AWS_IAM",
      credentials: {
        accessKeyId: process.env.AWS_ACCESS_KEY_ID,
        secretAccessKey: process.env.AWS_SECRET_ACCESS_KEY,
        sessionToken: process.env.AWS_SESSION_TOKEN,
      },
    },
    disableOffline: true,
  });

  const mutation = gql`
    mutation createPlayer(
      $name: String!
      $cognitoID: String!
      $username: String!
      $email: AWSEmail!
    ) {
      createPlayer(
        input: {
          cognitoID: $cognitoID
          email: $email
          name: $name
          username: $username
        }
      ) {
        id
      }
    }
  `;

  try {
    await graphqlClient.mutate({
      mutation,
      variables: {
        name: event.request.userAttributes.name,
        username: event.userName,
        cognitoID: event.request.userAttributes.sub,
        email: event.request.userAttributes.email,
      },
    });
    callback(null, event);
  } catch (error) {
    callback(error);
  }
};

GraphQL Schema(相关部分)

type Player
  @model
  @auth(
    rules: [
      { allow: private, operations: [read] }
      { allow: owner, ownerField: "username", operations: [update] }
      {
        allow: private
        provider: iam
        operations: [read, create, update, delete]
      }
    ]
  ) {
  id: ID!
  cognitoID: String!
  username: String! @primaryKey
  name: String!
  email: AWSEmail!
}

解决方案

1. 修正Lambda的凭证获取方式

Lambda运行时会自动注入执行角色的临时凭证,无需手动从环境变量读取。修改AWSAppSyncClient的初始化代码,使用AWS SDK默认凭证链:

// 顶部新增AWS SDK引入
const AWS = require('aws-sdk');

// 替换原有的client初始化代码
const graphqlClient = new appsync.AWSAppSyncClient({
  url: process.env.API_TICTACTOE010147_GRAPHQLAPIENDPOINTOUTPUT,
  region: process.env.REGION,
  auth: {
    type: "AWS_IAM",
    credentials: AWS.config.credentials // 使用默认凭证链
  },
  disableOffline: true,
});

2. 给Lambda执行角色添加AppSync权限

为Lambda的执行角色附加以下IAM策略,允许调用createPlayer mutation:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "appsync:GraphQL",
      "Resource": "arn:aws:appsync:<你的AWS区域>:<你的AWS账号ID>:apis/<你的AppSync API ID>/types/Mutation/fields/createPlayer"
    }
  ]
}

替换占位符为实际的区域、账号ID和AppSync API ID。

3. 确认AppSync启用IAM认证

进入AppSync控制台,找到目标API,在Settings的Authentication providers中,确保AWS IAM已启用。

4. 验证Schema的授权规则

当前Schema中的@auth规则已包含允许IAM执行create操作,无需修改:

{
  allow: private
  provider: iam
  operations: [read, create, update, delete]
}

完成以上步骤后,重新部署Lambda函数和AppSync API,即可解决授权错误。

内容的提问来源于stack exchange,提问作者Muhammad Umair Alim

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 17:54:51