Skip to content

feat(feedback): Send feedback from the profile menu, as a pre-filled GitHub issue - #486

Merged
huyplb merged 2 commits into
mainfrom
feat/send-feedback
Oct 6, 2026
Merged

huyplb merged 2 commits into
mainfrom
feat/send-feedback

Conversation

@huyplb

@huyplb huyplb commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Adds Send feedback to the profile menu. A reader picks Something is wrong, An idea or A question, writes a title and details, and clicks Open on GitHub. A new issue on tedious-code/foxSchema opens in a new tab, filled in. The reader reviews it and submits it with their own GitHub account.

Why the issue isn't posted by the app

Fox Schema holds no GitHub token and posts nothing. A token shipped with every self-hosted install could be read by anyone running one, who could then file issues as the project. The cost is that the reader needs a GitHub account and makes one more click, on a page where they can still edit or drop the issue. If a hosted instance should ever post directly, a server-side path with an operator-configured token can be added later, behind a setting.

Safeguards, since issues are public

  • Include app details adds the version, browser, workspace and the engines in use (postgres, oracle). It never adds a host, database or connection name. The dialog shows every line it would add, and the reader can untick it.
  • A line that looks like a password is flagged before anything is sent. That covers a credentialed URL, or an account statement the migration scrubber would rewrite (PASSWORD '…', IDENTIFIED BY …). This reuses findLeftoverSecrets and scrubSecrets from @foxschema/sql.
  • GitHub rejects new-issue URLs over about 8 KB, and the reader would lose what they typed. A description that long is shortened to the longest prefix that fits, and the dialog says so. Title and app details are kept whole.

Size

The dialog loads on first click (4.7 KB gzip). The first visit stays within the 170 KB budget (npm run bundle:first-load passes).

Tests

  • feedbackIssue.test.ts: URL and labels, characters special in URLs, the truncation search with multi-byte text, and the secret detection.
  • FeedbackDialog.test.tsx: opens one tab with the right URL; the details name no server and can be left out; the password warning; the truncation notice; Escape, Cancel and backdrop close it. A/B checked: leaking hosts into the details, or dropping the warning, fails it.
  • ProfileMenu.test.tsx: any role can open it from the menu.
  • apps/e2e/src/tests/send-feedback.test.ts: in a real browser, with window.open stubbed so nothing reaches GitHub. It needs no database, so it's added to the cloud e2e suite (run-cloud.mjs) and run-all.mjs.
  • npx vitest run: 5854 passed. Typecheck, eslint and npm run test-ids are clean.

Docs: USER_GUIDE "Send feedback" section and an UNRELEASED note.

🤖 Generated with Claude Code

https://claude.ai/code/session_016PyNv48vpYUw2HhpjYFNUi


Generated by Claude Code


Note

Low Risk
Additive client-only UI with no auth or server changes; privacy safeguards are tested but users can still paste sensitive data into public GitHub issues.

Overview
Adds Send feedback on the profile menu so signed-in users can file bugs, ideas, or questions as a pre-filled GitHub issue on tedious-code/foxSchema via Open on GitHub (window.open); the app does not post issues or hold a GitHub token.

The new FeedbackDialog (lazy-loaded like the admin panel) collects kind, title, and description, optionally attaches app details (version, browser, workspace, engine dialects only—no hosts or connection names), warns on lines that look like secrets (reusing @foxschema/sql scrub helpers), and shortens oversized bodies so the new-issue URL stays under GitHub’s limit.

Coverage includes unit tests for feedbackIssue and the dialog, a ProfileMenu test for any role, browser e2e (send-feedback.test.ts) wired into test:feedback, run-all.mjs, and run-cloud.mjs, plus generated test IDs and USER_GUIDE / UNRELEASED docs.

Reviewed by Cursor Bugbot for commit 05455e7. Bugbot is set up for automated code reviews on this repo. Configure here.

claude added 2 commits October 6, 2026 16:27
…GitHub issue

The profile menu gains "Send feedback": a bug, an idea or a question, a title
and the details. "Open on GitHub" opens a new issue on tedious-code/foxSchema
in a new tab, filled in, which the reader reviews and submits with their own
GitHub account. Fox Schema holds no token and posts nothing: a token shipped
with every self-hosted install would be readable by anyone running one.

Issues are public, so:
- "Include app details" lists every line it adds before anything is sent
  (version, browser, workspace, the engines in use) and names no host,
  database or connection; it can be unticked.
- A line that looks like it carries a password (a credentialed URL, or an
  account statement the migration scrubber would rewrite) is flagged.
- A description too long for a link (GitHub refuses ~8 KB URLs and the
  reader would lose what they typed) is shortened to fit, and says so.

The dialog loads on the first click (4.7 KB gzip); first visit stays within
the 170 KB budget. Unit and component tests, plus a DB-free e2e that runs in
the cloud e2e suite.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016PyNv48vpYUw2HhpjYFNUi
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016PyNv48vpYUw2HhpjYFNUi
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Test IDs

Added (14)

  • feedback-cancel
  • feedback-close
  • feedback-description
  • feedback-details
  • feedback-dialog
  • feedback-include-details
  • feedback-kind
  • feedback-kind-{…}
  • feedback-open-github
  • feedback-secret-warning
  • feedback-sent
  • feedback-title
  • feedback-truncated
  • profile-send-feedback

{…} is a part filled in at run time. The full tree: docs/testing/TEST_IDS.md.

@cursor

cursor Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: 200af3fb-9b1f-4198-9380-c699091aeb7f)

@huyplb
huyplb merged commit bb55de2 into main Oct 6, 2026
13 checks passed
@huyplb
huyplb deleted the feat/send-feedback branch October 6, 2026 16:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants