Skip to content

Commit

Permalink
chore: merge main into next-release/main (#7260)
Browse files Browse the repository at this point in the history
* Minor edits to Vite + React quickstart (#6926)

* Updates to Vite + React quickstart

* Update src/fragments/gen2/quickstart/build-a-backend.mdx

Co-authored-by: Kevin Old <[email protected]>

* Update build-a-backend.mdx

* Update build-a-backend.mdx

* Update build-a-backend.mdx

---------

Co-authored-by: Kevin Old <[email protected]>

* fix: Fix incorrect auth import path in migration guide. (#6934)

* fix: Update incorrect `updateMFAPreference` parameter in JS v6 migration guide. (#6935)

* Amplify Android Release 2.14.11 (#6933)

* chore: refactor .layout-header into separate component (#6826)

* platform typed as optional

* refactor init

* remove commented code

* remove angry useEffect

* fix typing

* added layoutcontext so mobile menu closes on navigation

* move import

---------

Co-authored-by: katiegoines <[email protected]>

* fix: Nesting of auth cli templates (#6932)

* fix: change config variable name (#6923)

* Guide to support Amplify v2 with AWS Android SDK (#6927)

* Update puppeteer (#6949)

* Update index.mdx (#6950)

* Update CODEOWNERS with correct PM alignment (#6951)

* fix(flutter, js): scope "connect existing cdk" guide to respective platform (#6947)

Co-authored-by: Tim Nguyen <[email protected]>

* Revert "fix(flutter, js): scope "connect existing cdk" guide to respective pl…" (#6955)

This reverts commit 5998b22.

* chore: remove duplicated logic between Layout and LayoutHeader (#6954)

* chore: more layout refactoring

* remove unused prop, alphabetize props

* improve oauth docs (#6961)

* fixed gen 2 getting started guide (#6968)

* Update redirects for deleted hidden pages (#6944)

* Update manual installation to point to @beta tag (#6972)

* include usage for multi-page apps (#6964)

* include usage for multi-page apps

* improve multi-page app docs

* use Hub syntax

* update imports in examples

* chore: Clean up broken Amplify JS API reference links (#6976)

* chore: Clean up broken Amplify JS API reference links.

* Cleaned up language.

* Update build image instructions for Gen 2 (#6978)

* update build image settings for Gen 2

* remove callout and add fragment to vite guide

* chore: add unit test for YoutubeEmbed component (#6983)

* chore: add unit test for YoutubeEmbed component

* add code coverage stats

---------

Co-authored-by: katiegoines <[email protected]>

* chore: add unit tests for Accordion component (#6981)

* chore: add unit tests for Accordion component

* issue with window properties

* fixed tracking test

* working on animation issue

* accordion tests

* fix testing errors

* added test for closing accordion

* add code coverage stats

---------

Co-authored-by: katiegoines <[email protected]>

* Update index.mdx (#6986)

* Add env variables for algolia (#6957)

* Add algolia env vars to next.config

* Remove extra code string

* fix(data): update REST API docs to document correct error response type (#6989)

* fix(data): update React Native minimum iOS deployment target guidance; add build step to docs (#6970)

* fix(data): update React Native minimum iOS deployment target; add build step to docs

* address PR feedback

* remove deployment target guidance

* add React Native version deployment target callout

* fix unrecognized syntax

* replace callout with accordion

* move 'upgrading' callout

* Clarify behavior of forgetDevice() API regarding device tracking (#6985)

* Clarify behavior of forgetDevice() API regarding device tracking

This commit updates the documentation to clarify that using the forgetDevice() API results in the device being neither remembered nor tracked. Previously, the documentation suggested that forgotten devices might still be tracked, leading to confusion about the API's behavior. The revised wording aligns with the detailed description under the "Forgotten" section, ensuring consistency and eliminating ambiguity about how forgotten devices are handled.

* Clarify behavior of forgetDevice() API regarding device tracking

* Support for enum value listing (#6885)

* Support for enum value listing

* Update src/pages/gen2/build-a-backend/data/data-modeling/add-fields/index.mdx

* CDK updates v2 (#6990)

* Add padding to bottom of nav menu (#6991)

* Adding secondary index to Gen 2 (#6996)

* Adding secondary index docs

* fixed some formatting for custom query fields

* extend config to show addOuput (#6963)

* extend config

* modify wording

* modify example

* improve wording

* Update index.mdx (#6995)

* Update index.mdx

* add guest access support to docs

* chore: add unit tests for NextPrevious component (#7003)

Co-authored-by: katiegoines <[email protected]>

* chore: add unit tests for LinkCards and LinkCard components (#7006)

Co-authored-by: katiegoines <[email protected]>

* chore: add unit tests for GetStartedPopover component (#7005)

Co-authored-by: katiegoines <[email protected]>

* fix: [Storage] Configure Access (#6948)

Co-authored-by: Tim Nguyen <[email protected]>

* fix(Swift): update data use policy info's tracking to false (#6938)

* fix(Swift): update data use policy info's tracking to false

* Update data-information.mdx

* chore: add callouts and troubleshooting guide for configuration (#6967)

* fix: resolve in-content broken links (#7011)

* re-platforming

* remove reference to mocking and testing for android & swift

* remove reference to mocking and testing for android & swift

* filtered out reference to optimistic ui for react native

---------

Co-authored-by: katiegoines <[email protected]>

* update gen2 storage and function docs (#7009)

* update gen2 storage and function docs

* add resource access links and example

* revisions, update code snippet titles

* Update CODEOWNERS (#7014)

* updated steps for extending components in code (#6827)

Co-authored-by: Aditya Shahani <[email protected]>

* Custom business logic support as of March @beta (#7019)

* Enhanced custom business logic DX

* addressed tim's comments

* Added custom subscription configuration worfklow

* removed in-development areas

* added titles

* added links for deep dive material

* Update src/pages/gen2/build-a-backend/data/custom-business-logic/index.mdx

Co-authored-by: josef <[email protected]>

* Update src/pages/gen2/build-a-backend/data/custom-business-logic/index.mdx

Co-authored-by: josef <[email protected]>

* Update src/pages/gen2/build-a-backend/data/custom-business-logic/index.mdx

Co-authored-by: Kethan sai <[email protected]>

* Update src/pages/gen2/build-a-backend/data/custom-business-logic/index.mdx

Co-authored-by: Kethan sai <[email protected]>

* Update src/pages/gen2/build-a-backend/data/custom-business-logic/index.mdx

Co-authored-by: josef <[email protected]>

* Update src/pages/gen2/build-a-backend/data/custom-business-logic/index.mdx

* added client method for clarity.

* Update src/pages/gen2/build-a-backend/data/custom-business-logic/index.mdx

Co-authored-by: Kethan sai <[email protected]>

* Apply suggestions from code review

Co-authored-by: josef <[email protected]>

---------

Co-authored-by: josef <[email protected]>
Co-authored-by: Kethan sai <[email protected]>

* add storage trigger docs (#7020)

* storage trigger docs

* Apply suggestions from code review

Co-authored-by: josef <[email protected]>

* add storage access actions

---------

Co-authored-by: josef <[email protected]>

* update link checker to wait for each call to complete before making t… (#6993)

* update link checker to wait for each call to complete before making the next and remove # from urls being checked

* update logging to show how many links found on each page

* Update tasks/link-checker.js

---------

Co-authored-by: Jacob Logan <[email protected]>
Co-authored-by: katiegoines <[email protected]>
Co-authored-by: Scott Rees <[email protected]>

* custom examples (#6979)

* custom examples

* fix: broken link, missing / at start (#7026)

Co-authored-by: katiegoines <[email protected]>

* validate and fix code snippets in Data section (#6975)

* Update sandbox --dir-to-watch description (#7031)

* Update index.mdx (#7035)

* Fix link (#7028)

* add docs to auth resource access pattern (#7032)

* fix: type platform as optional in Breadcrumbs component & add unit tests (#6912)

* platform typed as optional

* chore: add unit tests for Breadcrumbs

* testing to include platform optional

* fix: type platform as optional

* add tests for override values

---------

Co-authored-by: katiegoines <[email protected]>

* fix: proper variable naming conventions for storage (#7033)

fix:  proper variable naming conventions for storage

* remove explicit file extension from gen2 imports (#6946)

Co-authored-by: Tim Nguyen <[email protected]>

* fix: Update diff code blocks to TypeScript with code highlights (#6905)

* add docs on granting defineFunction access to defineData (#7029)

* standardize Gen 2 wording (#7036)

* Update index.mdx (#6906)

* Modify_Amplify_resources (#7018)

* fix code snippets on read data page

* code snippet updates

* updated the code snippets

* updated code snippets.

* custom business page rollback

* Update maplibre links (#7040)

* chore: add unit tests for PlatformNavigator (#6980)

* chore: add unit tests for PlatformNavigator

* add code coverage

* simplify

* simplify

---------

Co-authored-by: katiegoines <[email protected]>

* Update links to expo docs (#7044)

* Update links to expo docs

* Update src/pages/[platform]/prev/build-a-backend/auth/add-social-provider/index.mdx

Co-authored-by: josef <[email protected]>

* Update src/pages/[platform]/prev/build-a-backend/auth/add-social-provider/index.mdx

Co-authored-by: josef <[email protected]>

---------

Co-authored-by: josef <[email protected]>

* chore: add unit tests for InternalLinkButton (#7000)

Co-authored-by: katiegoines <[email protected]>

* chore: add addtl unit test for Block component (#6982)

* chore: add addtl unit test for Block component

* add code coverage stats

* remove superfluous Block component

---------

Co-authored-by: katiegoines <[email protected]>

* chore: add unit tests for TOC (#6984)

* chore: add unit tests for TOC

* add code coverage

* hardcode expected hash

---------

Co-authored-by: katiegoines <[email protected]>

* chore: add unit tests for ExternalLink (#6915)

* chore: add unit tests for ExternalLink

* fixing tracking test

---------

Co-authored-by: katiegoines <[email protected]>

* chore: add unit tests for ExternalLinkButton (#6914)

* chore: add unit tests for ExternalLinkButton

* Update ExternalLinkButton.test.tsx

triggering checks

---------

Co-authored-by: katiegoines <[email protected]>

* chore: add unit tests for Footer component (#6999)

Co-authored-by: katiegoines <[email protected]>

* chore: add unit tests for MigrationAlert component (#7004)

* chore: add unit tests for MigrationAlert component

* chore: add unit tests for MigrationAlert component

---------

Co-authored-by: katiegoines <[email protected]>

* chore: add unit test for Overview component (#7002)

Co-authored-by: katiegoines <[email protected]>

* chore: upgrade docsearch/react to 3.6 (#7046)

* added utility type content (#7047)

* chore: add unit tests for PageLastUpdated (#7001)

Co-authored-by: katiegoines <[email protected]>

* chore: add unit tests for Commands and Columns (#6916)

* chore: add unit test for CLICommands

* chore: add unit test for Columns

* Update Command.test.tsx

triggering checks

---------

Co-authored-by: katiegoines <[email protected]>

* Update resolution for follow-redirects (#7055)

* Update relative urls (#7048)

* Update relative urls

* Update url

* Updating link checker (#7052)

* Updating link checker to account for duplicate urls from different pages and link text

* Update slack formatting

* Remove console.log

* Add comments to function

* Remove extra console.logs()

* chore: update redirects list (#6969)

* update redirects

* updated redirects

---------

Co-authored-by: katiegoines <[email protected]>

* remove allowlist role names for appsync console access page (#7081)

* Add JavaScript resolver code sample to Gen 1 (#7087)

* fix(JS): Update v5 JS libraries installation guides. (#7090)

* fix(v5): update aws-amplify v5 dependency

* chore: remove extra '0' number from versions

* chore: remove vue2 block

* chore: update version reference

* Cbonif/field-level-auth-support-for-sql (#7091)

* chore(gen2-data): update .secondaryIndexes example to match the latest interface (#7095)

* update setup auth client example with correct props (#7106)

* update auth with correct props

* Change generated function env package name (#7096)

* Update typo in url for localhost (#7110)

* update next config to use a static build Id (#7102)

Co-authored-by: Jacob Logan <[email protected]>

* chore: Add callout on Analytics buffer persistence in Amplify JS (#7115)

* chore: Add callout on Analytics buffer persistence in Amplify JS.

* PR feedback.

* Custom subscription docs to Gen 2 (#7120)

* Add playsInline to videos (#7125)

* autoSignIn position correction in v6 migration docs (#7059)

* fix(next-release/main): update home page h1 and code block font size (#7117) (#7126)

* update font sizes

* add text-size-adjust

* add webkit prefix, add comment

* update text-size-adjust fix

---------

Co-authored-by: Tim Nguyen <[email protected]>

* remove parenthesis from "Amplify (Gen 2)" (#7113)

* change "NPM" to "npm" (#7112)

* remove explicit ".js" extension from gen2 resource imports (#7134)

* remove leading slash from storage access paths (#7116)

* remove unnecessary "Angular" mention in auth getting started (#7139)

Removed 'Angular' from the app description. It is not necessarily an angular app.

* Gen 2 Quickstart: Fix amplify console link (#7141)

* fix amplify console link

* fix text from AWS Console to Amplify Console

* updated alt text for Amplify console

* Update src/fragments/gen2/quickstart/deploy-and-host.mdx

Co-authored-by: Scott Rees <[email protected]>

* Update src/pages/gen2/deploy-and-host/fullstack-branching/branch-deployments/index.mdx

Co-authored-by: Scott Rees <[email protected]>

---------

Co-authored-by: Scott Rees <[email protected]>

* Add Favicon and apple-touch icons to root (#7137)

* add 96x96 favicons

* add favicon and apple-touch to root

* updated icons

---------

Co-authored-by: Jacob Logan <[email protected]>

* docs(migration): fixes mislabeling notification enable snippet (#7135)

the v5 snippet was labeled as v6 and the v6 was labeled as v5

Co-authored-by: derrik.fleming <[email protected]>

* edits to custom business logic (#7129)

* remove console.log (#7147)

* fix: copied code no longer includes markdown comments (#7146)

* fix: copied code no longer includes markdown comments

* minor cleanup

* splite prepareCopyText to it's own export for easier testing

* fix MDXCode mock

* chore(react-native): Add callouts for dropped Expo Go support (#7160)

* Update index.mdx (#7165)

* Update github link to maplibre repo (#7162)

* Cbonif/add-sql-support-for-secrets-manager (#7104)

* add image example for secrets manager key/value

* add documentation for creating secrets in secrets manager and configuring db details on the construct

* adjust order of paragraphs, moving relevant text closer to image and make alt text more descriptive

* Fixed typo in amplifyconfiguration.json for predictions (#7185)

* fix swift docs to use the `.update` call (#7191)

* Update index.mdx (#7164)

* Added documentation on updated IAM behavior (#7056)

* Added documentation on updated IAM behavior

* Update src/pages/[platform]/tools/cli/migration/iam-auth-updates-for-cdk-construct/index.mdx

Co-authored-by: Kamil Sobol <[email protected]>

* Update src/pages/[platform]/build-a-backend/graphqlapi/customize-authorization-rules/index.mdx

Co-authored-by: Kamil Sobol <[email protected]>

* Update src/pages/[platform]/build-a-backend/graphqlapi/customize-authorization-rules/index.mdx

* Update src/pages/[platform]/tools/cli/migration/iam-auth-updates-for-cdk-construct/index.mdx

* Update src/pages/[platform]/tools/cli/migration/iam-auth-updates-for-cdk-construct/index.mdx

Co-authored-by: Tim Schmelter <[email protected]>

* addressed comments

* Updated to reflect changes to Gen 2 content

* Update src/pages/[platform]/build-a-backend/graphqlapi/customize-authorization-rules/index.mdx

---------

Co-authored-by: Kamil Sobol <[email protected]>
Co-authored-by: Tim Schmelter <[email protected]>

* Added Metadata section in Storage (#7152)

* Cbonif/edits-to-secondary-indexes-page (#7179)

* edits to custom business logic

* update secondary index code examples

* Add client examples of accessing models with specific auth modes (#7080)

* add client side code for public access

* add client side code for signed in user access

* add client side code for multi user access

* add client side code for per user/owner access

* add client side code for custom id & group claims

* add client side code for custom access

* add client side code for user pool group access

* add client side code for oidc access

* Update src/pages/gen2/build-a-backend/data/customize-authz/signed-in-user-data-access/index.mdx

Co-authored-by: Rene Brandel <[email protected]>

* add info callout and configuration code to public/private iam examples

* move callout up

* remove "**note**" from callouts

---------

Co-authored-by: Rene Brandel <[email protected]>

* Updated Gen 2 relationship behavior (#7222)

* Added new relationship behavior doc

* fixed typos

* fix(predictions): fix wrong reference of swfit/android predictions use aws sdk page (#7220)

* fix(predictions): fix wrong reference of swfit/android predictions use aws sdk page

* fix(predictions): update Use AWS SDK description

* Update amplify/data/increment-like.js syntax (#7229)

The correct DynamoDB syntax requires semicolon in both expression and expressionValues

* Graphql generate client code (#7176)

* updated generate-client-code section

* updated graphql-client-code section

* updated the description

* removed workflow

* Update src/pages/gen2/reference/cli-commands/index.mdx

Co-authored-by: Rene Brandel <[email protected]>

* Update src/pages/gen2/reference/cli-commands/index.mdx

Co-authored-by: Rene Brandel <[email protected]>

* added Supported GraphQL client code combinations

* fixed the spell

* fixed the format

* fixed the syntax

* Update src/pages/gen2/reference/cli-commands/index.mdx

Co-authored-by: josef <[email protected]>

* Update src/pages/gen2/reference/cli-commands/index.mdx

Co-authored-by: josef <[email protected]>

* Update src/pages/gen2/reference/cli-commands/index.mdx

Co-authored-by: josef <[email protected]>

* Update src/pages/gen2/reference/cli-commands/index.mdx

Co-authored-by: josef <[email protected]>

* updated the stack name

---------

Co-authored-by: Rene Brandel <[email protected]>
Co-authored-by: josef <[email protected]>

* use latest tag for Gen2 apps (#7256)

* Updated Data Gen 2 authorization rules to use the new syntax (#7252)

* Updated authorization rules to use the new syntax

* Update src/pages/gen2/build-a-backend/data/customize-authz/signed-in-user-data-access/index.mdx

Co-authored-by: Hui Zhao <[email protected]>

---------

Co-authored-by: Hui Zhao <[email protected]>

---------

Co-authored-by: Jim Eagan <[email protected]>
Co-authored-by: Kevin Old <[email protected]>
Co-authored-by: Jim Blanchard <[email protected]>
Co-authored-by: Ankit Shah <[email protected]>
Co-authored-by: katiegoines <[email protected]>
Co-authored-by: Dan Kiuna <[email protected]>
Co-authored-by: Kihara, Takuya <[email protected]>
Co-authored-by: Tyler Roach <[email protected]>
Co-authored-by: Tim Nguyen <[email protected]>
Co-authored-by: Rene Brandel <[email protected]>
Co-authored-by: Elijah Quartey <[email protected]>
Co-authored-by: Heather Buchel <[email protected]>
Co-authored-by: John Corser <[email protected]>
Co-authored-by: Heather Pundt <[email protected]>
Co-authored-by: Nikhil Swaminathan <[email protected]>
Co-authored-by: Jay Raval <[email protected]>
Co-authored-by: David McAfee <[email protected]>
Co-authored-by: Kethan sai <[email protected]>
Co-authored-by: Michael Law <[email protected]>
Co-authored-by: erinleigh90 <[email protected]>
Co-authored-by: Edward Foyle <[email protected]>
Co-authored-by: Adi <[email protected]>
Co-authored-by: Aditya Shahani <[email protected]>
Co-authored-by: josef <[email protected]>
Co-authored-by: jacoblogan <[email protected]>
Co-authored-by: Jacob Logan <[email protected]>
Co-authored-by: Scott Rees <[email protected]>
Co-authored-by: Chris Bonifacio <[email protected]>
Co-authored-by: Roshane Pascual <[email protected]>
Co-authored-by: Charles Shin <[email protected]>
Co-authored-by: Ujjwol Shrestha <[email protected]>
Co-authored-by: Gen Tamura <[email protected]>
Co-authored-by: dwittle <[email protected]>
Co-authored-by: Anil Maktala <[email protected]>
Co-authored-by: israx <[email protected]>
Co-authored-by: Hui Zhao <[email protected]>
Co-authored-by: Nairi Areg <[email protected]>
Co-authored-by: spivakov83 <[email protected]>
Co-authored-by: Harshita Daddala <[email protected]>
Co-authored-by: derrik <[email protected]>
Co-authored-by: derrik.fleming <[email protected]>
Co-authored-by: Chris F <[email protected]>
Co-authored-by: Kamil Sobol <[email protected]>
Co-authored-by: Tim Schmelter <[email protected]>
Co-authored-by: yuhengshs <[email protected]>
Co-authored-by: Di Wu <[email protected]>
Co-authored-by: Guy Pavlov <[email protected]>
  • Loading branch information
Show file tree
Hide file tree
Showing 27 changed files with 347 additions and 245 deletions.
10 changes: 5 additions & 5 deletions src/fragments/gen2/quickstart/build-a-backend.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ const schema = a.schema({
.model({
content: a.string()
})
.authorization([a.allow.owner(), a.allow.public().to(['read'])])
.authorization(allow => [allow.owner(), allow.publicApiKey().to(['read'])])
});

export type Schema = ClientSchema<typeof schema>;
Expand All @@ -36,7 +36,7 @@ export const data = defineData({
schema,
authorizationModes: {
defaultAuthorizationMode: 'apiKey',
// API Key is used for a.allow.public() rules
// API Key is used for allow.publicApiKey() rules
apiKeyAuthorizationMode: {
expiresInDays: 30
}
Expand Down Expand Up @@ -99,7 +99,7 @@ const schema = a.schema({
priority: a.enum(['low', 'medium', 'high'])
// highlight-end
})
.authorization([a.allow.owner(), a.allow.public().to(['read'])]),
.authorization(allow => [allow.owner(), allow.publicApiKey().to(['read'])]),
});

// ...
Expand All @@ -114,12 +114,12 @@ The `Todo` data model is defined with authorization rules to allow the person wh
**Note:** These authorization rules can be modified using a chain of methods as defined by default. For example, we could remove the `.to(['read'])` and allow all visitors to perform all actions on data or add permissions for signed-in users or users who belong to user groups such as `Admin`. You can learn more about all options for authorization in the [Customize your auth rules](/[platform]/build-a-backend/data/customize-authz/) section of the docs.
</Callout>

<b>Step 2:</b> Remove public access by deleting the `a.allow.public().to(['read'])` authorization rule. Your authorization rule will look like the code below:
<b>Step 2:</b> Remove public access by deleting the `allow.publicApiKey().to(['read'])` authorization rule. Your authorization rule will look like the code below:

```js title="amplify/data/resource.ts"
// ...

.authorization([a.allow.owner()]),
.authorization(allow => [allow.owner()]),

// ...
```
Expand Down
2 changes: 1 addition & 1 deletion src/fragments/gen2/quickstart/create-amplify.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
The easiest way to get started with AWS Amplify is through npm with `create-amplify`.

```bash showLineNumbers={false}
npm create amplify@beta
npm create amplify@latest
```

```console showLineNumbers={false}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -109,7 +109,7 @@ import { schema as rdsSchema } from './schema.rds.ts'

// Add an authorization rule to the schema
// highlight-next-line
rdsSchema.models.Todo.authorization([a.allow.public()])
rdsSchema.models.Todo.authorization(allow => [allow.publicApiKey()])

const schema = a.schema({
Todo: a.model({
Expand Down Expand Up @@ -146,7 +146,7 @@ const schema = a.schema({
content: a.string()
isDone: a.boolean()
})
}).authorization([a.allow.public()])
}).authorization(allow => [allow.publicApiKey()])

const combinedSchema = a.schema.combine([
schema,
Expand Down Expand Up @@ -183,7 +183,7 @@ rdsSchema.addQueries({
ST_MakePoint(:lat, :long)
) <= :radiusInMeters
`)
.authorization([a.allow.public()])
.authorization(allow => [allow.publicApiKey()])
})
// highlight-end

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -70,7 +70,7 @@ const schema = a.schema({
// return type of the query
.returns(a.ref('EchoResponse'))
// only allow signed-in users to call this API
.authorization([a.allow.private()])
.authorization(allow => [allow.authenticated()])
});

export type Schema = ClientSchema<typeof schema>;
Expand Down Expand Up @@ -105,7 +105,7 @@ const schema = a.schema({
// return type of the query
.returns(a.ref('Post'))
// only allow signed-in users to call this API
.authorization([a.allow.private()])
.authorization(allow => [allow.authenticated()])
});

export type Schema = ClientSchema<typeof schema>;
Expand Down Expand Up @@ -166,7 +166,7 @@ const schema = a.schema({
.query()
.arguments({ content: a.string() })
.returns(a.ref('EchoResponse'))
.authorization([a.allow.public()])
.authorization(allow => [allow.publicApiKey()])
// 3. set the function has the handler
.handler(a.handler.function(echoHandler))
});
Expand Down Expand Up @@ -202,17 +202,17 @@ const schema = a.schema({
Post: a.model({
content: a.string(),
likes: a.integer()
.authorization([a.allow.private().to(['read'])])
}).authorization([
a.allow.owner(),
a.allow.private().to(['read'])
.authorization(allow => [allow.authenticated().to(['read'])])
}).authorization(allow => [
allow.owner(),
allow.authenticated().to(['read'])
]),

likePost: a
.mutation()
.arguments({ postId: a.id() })
.returns(a.ref('Post'))
.authorization([a.allow.private()])
.authorization(allow => [allow.authenticated()])
.handler(a.handler.custom({
dataSource: a.ref('Post'),
entry: './increment-like.js'
Expand All @@ -224,7 +224,7 @@ export type Schema = ClientSchema<typeof schema>;
export const data = defineData({
schema,
authorizationModes: {
defaultAuthorizationMode: 'userPool',
defaultAuthorizationMode: 'apiKey',
apiKeyAuthorizationMode: {
expiresInDays: 30
}
Expand All @@ -239,7 +239,7 @@ export function request(ctx) {
key: util.dynamodb.toMapValues({ id: ctx.args.postId}),
update: {
expression: 'ADD likes :plusOne',
expressionValues: { 'plusOne': { N: 1 } },
expressionValues: { ':plusOne': { N: 1 } },
}
}
}
Expand Down Expand Up @@ -295,17 +295,17 @@ const schema = a.schema({
Post: a.model({
content: a.string(),
likes: a.integer()
.authorization([a.allow.private().to(['read'])])
}).authorization([
a.allow.owner(),
a.allow.private().to(['read'])
.authorization(allow => [allow.authenticated().to(['read'])])
}).authorization(allow => [
allow.owner(),
allow.authenticated().to(['read'])
]),

likePost: a
.mutation()
.arguments({ postId: a.id() })
.returns(a.ref('Post'))
.authorization([a.allow.private()])
.authorization(allow => [allow.authenticated()])
.handler(a.handler.custom({
// highlight-next-line
dataSource: "ExternalTableDataSource",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ const schema = a.schema({
})
.returns(a.ref('Message'))
.handler(a.handler.custom({ entry: './publish.js' }))
.authorization([a.allow.public()]),
.authorization(allow => [allow.publicApiKey()]),

// highlight-start
// Subscribe to incoming messages
Expand All @@ -72,13 +72,13 @@ const schema = a.schema({
// subscription handler to set custom filters
.handler(a.handler.custom({entry: './receive.js'}))
// authorization rules as to who can subscribe to the data
.authorization([a.allow.public()]),
.authorization(allow => [allow.publicApiKey()]),
// highlight-end

// A data model to manage channels
Channel: a.model({
name: a.string(),
}).authorization([a.allow.public()]),
}).authorization(allow => [allow.publicApiKey()]),
});

export type Schema = ClientSchema<typeof schema>;
Expand Down Expand Up @@ -179,14 +179,14 @@ const schema = a.schema({
.handler(a.handler.custom({
entry: "./publish.js"
}))
.authorization([a.allow.private()]),
.authorization(allow => [allow.authenticated()]),
// Subscribe to all events from the "publish" mutation
receive: a.subscription(['publish'])
// highlight-next-line
.arguments({ name: a.string() })
.returns(a.ref('Channel'))
.authorization([a.allow.public()])
.authorization(allow => [allow.publicApiKey()])
});
export type Schema = ClientSchema<typeof schema>;
export const data = defineData({
Expand All @@ -203,7 +203,7 @@ import { type ClientSchema, a, defineData } from '@aws-amplify/backend';
const schema = a.schema({
Channel: a.model({
name: a.string(),
}).authorization([a.allow.public()]),
}).authorization(allow => [allow.publicApiKey()]),

Message: a.customType({
content: a.string().required(),
Expand All @@ -217,15 +217,15 @@ const schema = a.schema({
})
.returns(a.ref('Message'))
.handler(a.handler.custom({ entry: './publish.js' }))
.authorization([a.allow.public()]),
.authorization(allow => [allow.publicApiKey()]),

receive: a.subscription()
.for(a.ref('publish'))
// highlight-next-line
.arguments({ namePrefix: a.string() })
.returns(a.ref('Message'))
.handler(a.handler.custom({entry: './receive.js'}))
.authorization([a.allow.public()])
.authorization(allow => [allow.publicApiKey()])
});

export type Schema = ClientSchema<typeof schema>;
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,9 +43,9 @@ const schema = a.schema({
postname: a.string(),
content: a.string(),
})
.authorization([
a.allow.owner().identityClaim('user_id'),
a.allow.specificGroups(['Moderator']).withClaimIn('user_groups'),
.authorization(allow => [
allow.owner().identityClaim('user_id'),
allow.groups(['Moderator']).withClaimIn('user_groups'),
]),
});

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ const schema = a.schema({
})
// STEP 1
// Indicate which models / fields should use a custom authorization rule
.authorization([a.allow.custom()]),
.authorization(allow => [allow.custom()]),
});

export type Schema = ClientSchema<typeof schema>;
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ const schema = a
})
})
// highlight-next-line
.authorization([a.allow.resource(functionWithDataAccess)]);
.authorization(allow => [allow.resource(functionWithDataAccess)]);

export type Schema = ClientSchema<typeof schema>;

Expand All @@ -59,7 +59,7 @@ export const data = defineData({
});
```

The object returned from `defineFunction` can be passed directly to `a.allow.resource()` in the schema authorization rules. This will grant the function the ability to execute Query, Mutation, and Subscription operations against the GraphQL API. Use the `.to()` method to narrow down access to one or more operations.
The object returned from `defineFunction` can be passed directly to `allow.resource()` in the schema authorization rules. This will grant the function the ability to execute Query, Mutation, and Subscription operations against the GraphQL API. Use the `.to()` method to narrow down access to one or more operations.

```ts
const schema = a
Expand All @@ -70,8 +70,8 @@ const schema = a
})
})
// highlight-start
.authorization([
a.allow.resource(functionWithDataAccess).to(['query', 'listen'])
.authorization(allow => [
allow.resource(functionWithDataAccess).to(['query', 'listen'])
]); // allow query and subscription operations but not mutations
// highlight-end
```
Expand Down
34 changes: 17 additions & 17 deletions src/pages/[platform]/build-a-backend/data/customize-authz/index.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -39,12 +39,12 @@ Use the `.authorization()` modifier to configure authorization rules for public,
const schema = a.schema({
Post: a.model({
content: a.string()
}).authorization([
}).authorization(allow => [
// Allow anyone auth'd with an API key to read everyone's posts.
a.allow.public().to(['read']),
allow.publicApiKey().to(['read']),
// Allow signed-in user to create, read, update,
// and delete their __OWN__ posts.
a.allow.owner(),
allow.owner(),
])
})
```
Expand Down Expand Up @@ -75,7 +75,7 @@ If there are multiple authorization rules present, they will be logically OR'ed.

To help you get started, you can define an authorization rule on the data schema that will be applied to all data models that **do not** have a model-level authorization rule. Instead of having a global authorization rule for all production environments, we recommend creating specific authorization rules for each model or field.

The global authorization rule below uses `a.allow.public()`. This example allows anyone to create, read, update, and delete and is applied to every data model.
The global authorization rule below uses `allow.publicApiKey()`. This example allows anyone to create, read, update, and delete and is applied to every data model.

```ts
const schema = a.schema({
Expand All @@ -89,11 +89,11 @@ const schema = a.schema({
Notes: a.model({
content: a.string()
// [Model-level authorization rule]
}).authorization([a.allow.public().to(['read'])])
}).authorization(allow => [allow.publicApiKey().to(['read'])])

// [Global authorization rule]
}).authorization([
a.allow.public()
}).authorization(allow => [
allow.publicApiKey()
])
```

Expand All @@ -109,9 +109,9 @@ const schema = a.schema({
// [Model-level authorization rule]
// All fields (content, createdBy) will be protected by
// this authorization rule
}).authorization([
a.allow.public().to(['read']),
a.allow.owner(),
}).authorization(allow => [
allow.publicApiKey().to(['read']),
allow.owner(),
])
})
```
Expand All @@ -133,13 +133,13 @@ const schema = a.schema({
// [Field-level authorization rule]
// This auth rule will be used for the "ssn" field
// All other fields will use the model-level auth rule
ssn: a.string().authorization([a.allow.owner()]),
ssn: a.string().authorization(allow => [allow.owner()]),
})

// [Model-level authorization rule]
.authorization([
a.allow.private().to(["read"]),
a.allow.owner()
.authorization(allow => [
allow.authenticated().to(["read"]),
allow.owner()
]),
});
```
Expand All @@ -155,9 +155,9 @@ const schema = a.schema({
Post: a.model({
title: a.string(),
content: a.string()
}).authorization([
a.allow.public("identityPool").to(["read"]),
a.allow.owner()
}).authorization(allow => [
allow.guest().to(["read"]),
allow.owner()
])
})
```
Expand Down
Loading

0 comments on commit e12c886

Please sign in to comment.