Conversation
The gen2-migration auth renderer did not emit a Schema override for the migrated UserPool. On the refactor UpdateUserPool against the imported Gen1 pool, the auth construct re-emitted a login-derived standard attribute without an AttributeDataType, which the service rejected with "Invalid AttributeDataType input". Emit each existing attribute with its AttributeDataType, its constraints, and Required: false, which is the one Schema shape valid on both the fresh CreateUserPool and the refactor UpdateUserPool. Auto-managed attributes and attributes without a data type are dropped, and no override statement is emitted when the pool has no schema.
sarayev
force-pushed
the
fix/gen2-migration-attribute-datatype-pr
branch
from
October 1, 2026 20:39
7de216f to
6da8a1b
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
During a gen1 to gen2 migration, the generated auth construct did not emit a Schema override for the migrated Cognito UserPool. On the refactor
UpdateUserPoolagainst the imported gen1 pool, the construct re-emitted a login-derived standard attribute (for exampleemail) without anAttributeDataType, and the service rejected the update withInvalid AttributeDataType input.Change
The auth renderer now emits a
Schemaoverride for the migrated UserPool. Each existing attribute is emitted with itsAttributeDataType, its constraints, andRequired: false. That is the one Schema shape that is valid on both the freshCreateUserPooland the refactorUpdateUserPoolagainst the imported pool:CreateUserPool(Schema must have length greater than or equal to 1);Required: truefails the refactorUpdateUserPool(Required custom attributes are not supported), because the service reads any required member on update as introducing a required attribute.Auto-managed attributes (for example
sub,email_verified) and attributes without a data type are dropped, and no override statement is emitted when the pool has no schema.Scope
Scoped to only this change. The commit is cut on top of #14991, which is reviewed separately.
Testing
auth.generator.test.tspasses with the regenerated inline snapshots; the migration-app_snapshot.post.generate/amplify/auth/resource.tsfixtures are regenerated to match.Invalid AttributeDataTypeorRequired custom attributeserrors.Note
The combined e2e run surfaces a separate, pre-existing failure in the migration rollback path (the Phase 2
amplify push --forcethat restores the gen1 backend hitsExisting schema attributes cannot be modified or deletedon the UserPool). That failure is unrelated to this change: it is in the rollback restore path, not the forward renderer, and a no-fix baseline run fails earlier (at the forward step) and never reaches it. It is being tracked separately.