Combining API KEY authorization "read" and "listen" access doesn't work

gpavlov2016 closed 4 days ago

gpavlov2016 commented 3 months ago

Amplify APIs

Authentication, GraphQL API

Describe the bug

Combining both read and listen permissions doesn't work.

const schema = a.schema({
  Video: a

      a.allow.public().to(['read', 'listen']),

Either listen or read on their own do work

Expected behavior

After saving the file with sandbox running the model is deployed

Reproduction steps

  1. Create a basic model (from sample app) and add authorization a.allow.public().to(['read', 'listen']) to amplify data\resource.ts
  2. npx amplify sandbox

Code Snippet

const schema = a.schema({
  Video: a
      title: a.string()
      a.allow.public().to(['read', 'listen']),

export type Schema = ClientSchema<typeof schema>;

export const data = defineData({
  authorizationModes: {
    defaultAuthorizationMode: 'userPool',
    apiKeyAuthorizationMode: {}

``` // Put your logs below this line Failed to instantiate data construct ```


Manual configuration

Additional configuration

Mobile Device

Mobile Operating System

Mobile Browser

Mobile Browser Version

Additional information and screenshots

chrisbonifacio commented 3 months ago

Hi @gpavlov2016 👋 it seems that this may be intended behavior. When I try to deploy the same schema, I get this error:

InvalidDirectiveError: 'listen' operations are specified in addition to 'read'. Either remove 'read' to limit access only to 'listen' or only keep 'read' to grant all get,list,search,listen,sync access.

read encompasses listen/subscribe permissions. Can you let us know what your use case is? For example, do you want the user to be able to subscribe without being able to perform list queries?

gpavlov2016 commented 3 months ago

Thanks for looking into this @chrisbonifacio. My scenario is:

When I try with read access only for public auth, the queries on Android work but the subscriptions fail. I did some digging into the Android amplify library and it seems like it is related to this comment

renebrandel commented 3 months ago

hi @gpavlov2016 the read operation includes listen access. So the listen operation in the list here is a no-op. So this might be a red herring.

Another common reason we see why subscription "come across as failing" is because the GraphQL selection set of the mutation must include all the fields that the subscriber is looking for. Can you share the code where you trigger the mutation and the Android code where you listen to the subscription?

gpavlov2016 commented 3 months ago

The subscription fails at the authentication stage before I even try to do any mutation, and based on the logs it's trying to use Cognito for authentication. Query operation with the same code succeeds. Here is how the model is defined in the React client:

const schema = a.schema({
  Video: a
      title: a.string(),
      timeOfDayStart: a.time(),
      timeOfDayEnd: a.time(),
      impressionsTarget: a.integer(),
      zipCode: a.string(),
      s3Key: a.string(),
      thumbnail: a.string(),
      isRunning: a.boolean(),
      a.allow.owner().to(['create', 'read', 'update', 'delete']),

export type Schema = ClientSchema<typeof schema>;

export const data = defineData({
  authorizationModes: {
    defaultAuthorizationMode: 'userPool',
    apiKeyAuthorizationMode: {}

And here is how the model is defined in the Android client (autogenerated from using amplify config file).

@ModelConfig(pluralName = "Videos", type = Model.Type.USER, version = 1, authRules = {
  @AuthRule(allow = AuthStrategy.PUBLIC, operations = { ModelOperation.READ }),
  @AuthRule(allow = AuthStrategy.OWNER, ownerField = "owner", identityClaim = "cognito:username", provider = "userPools", operations = { ModelOperation.CREATE, ModelOperation.READ, ModelOperation.UPDATE, ModelOperation.DELETE })
}, hasLazySupport = true)
public final class Video implements Model {

And this is the code that calls the subscribe method:

val onCreateSubscription = Amplify.API.subscribe(
            { Log.i("ApiQuickStart", "Subscription established - onCreate") },
                Log.i("ApiQuickStart", "Video create subscription received: ${( as Video).title}")
            { Log.e("ApiQuickStart", "Subscription failed - onCreate", it) },
            { Log.i("ApiQuickStart", "Subscription completed - onCreate") }

For reference, this is the query call that works with the same settings:

            ModelQuery.list(, Video.IS_RUNNING.eq(true)),
            { response ->
                val page =
                Log.d("refreshItems", page.toString())
                Log.i("MyAmplifyApp", "Queried items: $page")
            { Log.e("MyAmplifyApp", "Query failure", it) }

Error message from logcat:

Subscription failed - onCreate ApiAuthException{message=Token is null, cause=null, recoverySuggestion=Sorry, we don't have a suggested fix for this error yet.} at at at at at at at at at com.amplifyframework.api.ApiCategory.subscribe( at com.example.androidamplifygen2.MainActivity.subscribe(MainActivity.kt:208) at com.example.androidamplifygen2.MainActivity.onCreate(MainActivity.kt:106) at at at at at at at at at$H.handleMessage( at android.os.Handler.dispatchMessage( at android.os.Looper.loop( at at java.lang.reflect.Method.invoke(Native Method) at$ at 2024-04-08 18:24:07.756 6648-6700 MyAmplifyApp com.example.androidamplifygen2 E Query failure ApiException{message=OkHttp client failed to make a successful request., cause=ApiAuthException{message=Failed to retrieve auth token from Cognito provider., cause=ApiAuthException{message=Token is null, cause=null, recoverySuggestion=Sorry, we don't have a suggested fix for this error yet.}, recoverySuggestion=Check the application logs for details.}, recoverySuggestion=Sorry, we don't have a suggested fix for this error yet.} at at$r8$lambda$s0tPt9Vu7puSi2-I-7S0nxLOkUY(Unknown Source:0) at$$$$SyntheticClass:0) at java.util.concurrent.Executors$ at at java.util.concurrent.ThreadPoolExecutor.runWorker( at java.util.concurrent.ThreadPoolExecutor$ at Caused by: ApiAuthException{message=Failed to retrieve auth token from Cognito provider., cause=ApiAuthException{message=Token is null, cause=null, recoverySuggestion=Sorry, we don't have a suggested fix for this error yet.}, recoverySuggestion=Check the application logs for details.} at at at at$r8$lambda$s0tPt9Vu7puSi2-I-7S0nxLOkUY(Unknown Source:0)  at$$$$SyntheticClass:0)  at java.util.concurrent.Executors$  at  at java.util.concurrent.ThreadPoolExecutor.runWorker(  at java.util.concurrent.ThreadPoolExecutor$  at  Caused by: ApiAuthException{message=Token is null, cause=null, recoverySuggestion=Sorry, we don't have a suggested fix for this error yet.} at at at at  at  at$r8$lambda$s0tPt9Vu7puSi2-I-7S0nxLOkUY(Unknown Source:0)  at$$$$SyntheticClass:0)  at java.util.concurrent.Executors$  at  at java.util.concurrent.ThreadPoolExecutor.runWorker(  at java.util.concurrent.ThreadPoolExecutor$  at 

chrisbonifacio commented 3 months ago

Hi @gpavlov2016 because the issue seems to be with auth in the android sdk, I am transferring this issue over to the amplify/android repo for better support.

joon-won commented 3 months ago

Hi @gpavlov2016, this is amplify android, our team will take a look into the issue

mattcreaser commented 2 months ago

Hey @gpavlov2016 thanks for your patience. I'll take a look into this.

gpavlov2016 commented 2 months ago

Thanks @mattcreaser ! The title is probably need to change since it's not about the access permissions in amplify-js but about support of api key auth in android based on the triage of the js team

mattcreaser commented 2 months ago

Definitely looks like the issue would be in the Multi-auth subscription operation, but we will know more after we investigate.

mattcreaser commented 2 months ago

Hi @gpavlov2016. I've been looking into this issue and have some updates to share.

The reason Amplify is trying to use the user pool is because that is the default authorization mode for your API. Normally you would get around this by choosing a new auth mode for your request. The current way to do this for Gen2 is using this builder API (we'll be adding a more convenient way to set this soon):

    val request = ModelSubscription.onCreate( as AppSyncGraphQLRequest
    val apiKeyRequest = request.newBuilder()

   val onCreateSubscription = Amplify.API.subscribe(apiKeyRequest, ...)

However, while testing this out I actually found a bug in Amplify's handling of multiple auth rules for subscriptions, so the above is not working as expected. I'll work on a fix for that, but in the meantime you can actually get the desired behaviour by requesting a multi-auth subscription:

    val request = ModelSubscription.onCreate( as AppSyncGraphQLRequest
    val multiAuthRequest = request.newBuilder()

  val onCreateSubscription - Amplify.API.subscribe(multiAuthRequest, ...)

That should allow you to subscribe to the video model without logging in. I'll update this issue again once the fix to directly use API_KEY in this situation becomes available.

mattcreaser commented 4 days ago

The bug mentioned above was fixed in Amplify Android 2.20.0.

We also have an in-progress feature to improve the experience for setting the auth mode for a request that will be included in a future release.

Closing this issue now!

