AWS Amplify GraphQL访问规则不生效问题求助
问题解决步骤
1. 修正GraphQL Schema的权限规则
当前的owner规则默认包含read操作,会导致已认证用户查询时仅返回自己的记录,同时未认证用户的访问权限也未正确生效。修改Schema如下:
type UserProfile @model @auth(rules: [ { allow: public, operations: [read] }, { allow: owner, operations: [create, update, delete] } ]) { content: String }
allow: public, operations: [read]:确保所有用户(认证/未认证)都能读取所有UserProfile记录allow: owner, operations: [create, update, delete]:仅允许所有者创建、更新、删除自己的UserProfile,移除read操作避免过滤其他用户的记录
2. 启用API的未认证访问权限
未认证用户查询报错是因为Amplify API默认未开启未认证访问,需要通过Amplify CLI配置:
- 运行命令:
amplify update api
- 选择你的GraphQL API,然后依次选择:
Configure auth settingsAllow unauthenticated users to access your API?→ 选择Yes
- 保存配置后,重新部署:
amplify push
3. 验证查询逻辑
你的Flutter查询代码无需修改,重新部署后:
- 未认证用户调用
queryUserProfile()将能获取所有UserProfile记录 - 已认证用户调用
queryUserProfile()也能获取所有记录,且仅能修改/删除自己创建的UserProfile
额外检查
确保Flutter项目中Amplify初始化正确包含Auth和API模块:
void configureAmplify() async { await Amplify.addPlugins([ AmplifyAuthCognito(), AmplifyAPI(modelProvider: ModelProvider.instance), ]); await Amplify.configure(amplifyconfig); }
内容的提问来源于stack exchange,提问作者farooq
相关产品推荐
相关产品推荐

