You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Amplify GraphQL访问规则不生效问题求助

问题解决步骤

1. 修正GraphQL Schema的权限规则

当前的owner规则默认包含read操作,会导致已认证用户查询时仅返回自己的记录,同时未认证用户的访问权限也未正确生效。修改Schema如下:

type UserProfile @model @auth(rules: [
  { allow: public, operations: [read] },
  { allow: owner, operations: [create, update, delete] }
]) {
  content: String
}
  • allow: public, operations: [read]:确保所有用户(认证/未认证)都能读取所有UserProfile记录
  • allow: owner, operations: [create, update, delete]:仅允许所有者创建、更新、删除自己的UserProfile,移除read操作避免过滤其他用户的记录

2. 启用API的未认证访问权限

未认证用户查询报错是因为Amplify API默认未开启未认证访问,需要通过Amplify CLI配置:

  1. 运行命令:
amplify update api
  1. 选择你的GraphQL API,然后依次选择:
    • Configure auth settings
    • Allow unauthenticated users to access your API? → 选择Yes
  2. 保存配置后,重新部署:
amplify push

3. 验证查询逻辑

你的Flutter查询代码无需修改,重新部署后:

  • 未认证用户调用queryUserProfile()将能获取所有UserProfile记录
  • 已认证用户调用queryUserProfile()也能获取所有记录,且仅能修改/删除自己创建的UserProfile

额外检查

确保Flutter项目中Amplify初始化正确包含Auth和API模块:

void configureAmplify() async {
  await Amplify.addPlugins([
    AmplifyAuthCognito(),
    AmplifyAPI(modelProvider: ModelProvider.instance),
  ]);
  await Amplify.configure(amplifyconfig);
}

内容的提问来源于stack exchange,提问作者farooq

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 09:37:57