Conversation
Submits one feedback item, filed under the account that owns the token. The body goes through --data, like every other JSON write; feedback.yaml now declares its fields so --schema and generate-skills describe them. create needs user-feedback:write, which mapbox auth login now asks for. POST /oauth/register drops it until mapbox/api-accounts#2152 is deployed, so until then a login gets a 403 on create. The Feedback API's 403 says "Access token does not have <scope> scope", which missing_scope didn't recognize, so it got the generic advice instead of the scope-specific one. It's recognized now. Verified against production with a token that has the scope: create returns 200 and the item, with place_name filled in; a repeated id gets 400 "already exists"; trace_id in the body is dropped; get reads the item at once, while list took 20-40 seconds to show it. A login token gets the 403 above. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
zmofei
force-pushed
the
feat/feedback-create
branch
from
October 2, 2026 12:32
fff41cb to
7ea707a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #49.
What
mapbox feedback createsubmits one feedback item, filed under the account that owns the token. The body goes through--data, like every other JSON write;feedback.yamlnow declares its fields (feedback,lat,lon,categoryrequired;id,feature,screenshotoptional) so--schemaandgenerate-skillsdescribe them.Scope.
createneedsuser-feedback:write, andmapbox auth loginnow asks for it.POST /oauth/registerdrops it until mapbox/api-accounts#2152 is deployed, so this should merge after that ships: until then a login gets a 403 oncreate. Logins from before this change needmapbox auth loginagain.403 advice. The Feedback API says
Access token does not have <scope> scope, whichremedy::missing_scopedidn't recognize, so it got the generic advice. It's recognized now, so the 403 names the scope and says how to get it for the token that was used.Verification
Against production, with a token that has
user-feedback:write:createreturns 200 and the item, withplace_namefilled in fromlat/lon.idagain gets 400Feedback with id … already exists., so a client-supplied UUID makes retries safe.trace_idin the body is dropped (trace_id: null).getreads the new item at once;listtook 20–40 seconds to show it.693 tests, fmt and clippy clean. The login-scope test fails with
user-feedback:writeremoved from the list.Not verified: an end-to-end
createwith a token frommapbox auth login, since that needs mapbox/api-accounts#2152 deployed. That asking for the scope before then is harmless (silently dropped, login still succeeds) comes from #49's registration test, not a fresh check.One test item was created in production (
77bf502a-…, accountmofei, marked as a test). The API has no delete, so it stays in the review queue.🤖 Generated with Claude Code