You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS DynamoDB普通用户查询无法返回自有数据 仅管理员权限可正常访问

问题根因

你遇到的普通用户无法查询自有数据的问题由两处Schema配置不匹配直接导致,和邮箱+密码的认证方式无关:

  • 你在@auth规则中指定了ownerField: "username"作为所有者匹配字段,但你定义的User模型中根本没有声明username字段,权限校验时无法读取对应值做对比,直接拦截了普通用户的查询请求。
  • AWS Amplify的owner鉴权默认会取当前登录用户Cognito信息中的sub(全局唯一ID)作为匹配值,如果你希望用邮箱作为所有者的匹配依据,需要显式指定identityClaim: "email",否则即便字段存在也会出现匹配失败的情况。

修复方案

你可以根据业务需求选择以下任意一种方案调整Schema:

方案1:使用默认sub匹配(更安全,推荐)

type User @model 
@auth(rules: [
{allow: groups, groups: ["Admin"] },
{allow: owner, ownerField: "ownerSub", operations: [read]}
])
{
  id: ID!
  email: String!
  ownerSub: String! # Amplify会在创建数据时自动填充当前用户的Cognito sub值
}

方案2:使用邮箱作为匹配依据

type User @model 
@auth(rules: [
{allow: groups, groups: ["Admin"] },
{allow: owner, ownerField: "email", identityClaim: "email", operations: [read]}
])
{
  id: ID!
  email: String!
}

修改完成后执行amplify push更新后端资源即可生效。

补充说明

GraphQL的owner属性完全支持邮箱+密码的认证方式,不存在仅支持用户名+密码认证的限制,只要保证ownerField指定的字段在模型中存在、且字段值和identityClaim指定的Cognito返回字段值一致就能通过鉴权校验。

内容的提问来源于stack exchange,提问作者DanielJackson

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.03 01:06:04