Skip to content

fix(aws-appsync): list caps, key ids and config cross-validation - #1370

Merged
NitinKumar004 merged 3 commits into
developmentfrom
fix/aws-appsync-s0
Sep 27, 2026
Merged

NitinKumar004 merged 3 commits into
developmentfrom
fix/aws-appsync-s0

Conversation

@NitinKumar004

Copy link
Copy Markdown
Collaborator

Summary

Work item S0 from the AppSync build-out plan. It brings list paging, API key ids and config checks in line with real AppSync. All behaviour lives in the provider (providers/aws/appsync).

List caps

  • Every AppSync List op in the service model caps maxResults at 25 with a minimum of 0. I checked each op in the botocore model and they all agree. The ops served today are ListGraphqlApis, ListDataSources and ListApiKeys.
  • A value over 25 returns BadRequestException with the standard constraint message. A negative value is rejected the same way.
  • The default page is now 25. It used to be 100.
  • The wire handler saturates an oversized query value, so a number too big for int32 can't wrap back into range.

API key ids

  • Keys are now da2- plus 26 random lowercase alphanumeric characters. They used to be sequential da2-%08x.

Config cross-validation (create and update)

  • Auth: AMAZON_COGNITO_USER_POOLS needs userPoolConfig, OPENID_CONNECT needs openIDConnectConfig and AWS_LAMBDA needs lambdaAuthorizerConfig. The same rules apply to each additionalAuthenticationProviders entry. A primary user pool config must have defaultAction set to ALLOW or DENY, otherwise the call fails with "Invalid default effect type".
  • Data sources: each type needs its own config block and the required strings inside it. A block that belongs to another type is rejected. serviceRoleArn is required for DynamoDB, Lambda, Elasticsearch, OpenSearch and EventBridge, and for HTTP when it signs with IAM. AMAZON_BEDROCK_RUNTIME is now accepted as a type.

Error wording

  • Taken from public AWS responses: "PipelineConfig can't be null." (terraform-provider-aws #35409 and #42044), "The validated string is empty" (#27498) and "Invalid default effect type" (aws-cdk #10028).
  • The other missing-block messages follow the same <Block> can't be null. pattern. I could not find a public capture of each one.
  • The mismatched-block message is our own wording. Its exception type is correct.

Regression test

Not in this PR

  • Resolver checks (UNIT vs PIPELINE with pipelineConfig, runtime vs requestMappingTemplate) are not here. Resolvers don't exist in cloudemu yet. They arrive with schema support in S1, and those checks belong with them.

Testing

  • Provider and wire tests were written first. They failed on the old code, apart from the ARN regression guard, which already passed.
  • go build ./..., then vet and go test -race on the touched packages. Lint with --new-from-rev=origin/development reports 0 issues. coveragegen output is unchanged.
  • aws CLI against cloudemu serve:
    • create-graphql-api for all five auth types;
    • create-api-key;
    • list ops with max-results, and 26 rejected;
    • tag, list and untag with the real ARN;
    • every cross-validation error above.
  • Terraform, using aws_appsync_graphql_api (Cognito + additional providers, and Lambda auth), aws_appsync_api_key and aws_appsync_datasource (NONE, HTTP, DynamoDB, Lambda): apply, then a clean plan. Next an update of name, key description, data-source description, HTTP endpoint and an added OIDC provider, then a clean plan again. Then destroy.

@NitinKumar004
NitinKumar004 marked this pull request as ready for review September 27, 2026 12:09
@NitinKumar004
NitinKumar004 merged commit e5f072f into development Sep 27, 2026
23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant