Skip to content

Add mapbox feedback create - #73

Open
zmofei wants to merge 1 commit into
feat/feedback-apifrom
feat/feedback-create
Open

zmofei wants to merge 1 commit into
feat/feedback-apifrom
feat/feedback-create

Conversation

@zmofei

@zmofei zmofei commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Stacked on #49.

What

mapbox feedback create submits one feedback item, filed under the account that owns the token. The body goes through --data, like every other JSON write; feedback.yaml now declares its fields (feedback, lat, lon, category required; id, feature, screenshot optional) so --schema and generate-skills describe them.

Scope. create needs user-feedback:write, and mapbox auth login now asks for it. POST /oauth/register drops it until mapbox/api-accounts#2152 is deployed, so this should merge after that ships: until then a login gets a 403 on create. Logins from before this change need mapbox auth login again.

403 advice. The Feedback API says Access token does not have <scope> scope, which remedy::missing_scope didn't recognize, so it got the generic advice. It's recognized now, so the 403 names the scope and says how to get it for the token that was used.

Verification

Against production, with a token that has user-feedback:write:

  • create returns 200 and the item, with place_name filled in from lat/lon.
  • The same id again gets 400 Feedback with id … already exists., so a client-supplied UUID makes retries safe.
  • trace_id in the body is dropped (trace_id: null).
  • get reads the new item at once; list took 20–40 seconds to show it.
  • A login token (no write scope yet) gets the 403, now with the scope-specific advice.

693 tests, fmt and clippy clean. The login-scope test fails with user-feedback:write removed from the list.

Not verified: an end-to-end create with a token from mapbox auth login, since that needs mapbox/api-accounts#2152 deployed. That asking for the scope before then is harmless (silently dropped, login still succeeds) comes from #49's registration test, not a fresh check.

One test item was created in production (77bf502a-…, account mofei, marked as a test). The API has no delete, so it stays in the review queue.

🤖 Generated with Claude Code

@zmofei
zmofei requested a review from a team as a code owner October 2, 2026 12:03
Submits one feedback item, filed under the account that owns the token.
The body goes through --data, like every other JSON write; feedback.yaml
now declares its fields so --schema and generate-skills describe them.

create needs user-feedback:write, which mapbox auth login now asks for.
POST /oauth/register drops it until mapbox/api-accounts#2152 is deployed,
so until then a login gets a 403 on create.

The Feedback API's 403 says "Access token does not have <scope> scope",
which missing_scope didn't recognize, so it got the generic advice
instead of the scope-specific one. It's recognized now.

Verified against production with a token that has the scope: create
returns 200 and the item, with place_name filled in; a repeated id gets
400 "already exists"; trace_id in the body is dropped; get reads the item
at once, while list took 20-40 seconds to show it. A login token gets the
403 above.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@zmofei
zmofei force-pushed the feat/feedback-create branch from fff41cb to 7ea707a Compare October 2, 2026 12:32
@zmofei zmofei self-assigned this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant