@auth rules filtering on id allows access to any resourse

You have to set the type of rule, query, i.e.

https://dgraph.io/docs/graphql/authorization/directive

J