Skip to content

Add styles download - #70

Merged
zmofei merged 5 commits into
mainfrom
feat/styles-download
Oct 1, 2026
Merged

zmofei merged 5 commits into
mainfrom
feat/styles-download

Conversation

@zmofei

@zmofei zmofei commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Adds mapbox styles download <style-id> > style.zip, now that the styles:download scope can be granted at login.

  • Spec (first commit): openapi/api-styles regenerated with downloadStyleZip enabled. The only change is the new operation.
  • Login: mapbox auth login now requests styles:download. Existing logins need to log in again.
  • Access check: the endpoint also requires the account to have access to it, which Mapbox grants per account and no token can carry. A 403 is now read for its cause:
    • "This is a prerelease API" → says to contact Mapbox at help@mapbox.com.
    • "requires a token with <scope> scope" → depends on where the token came from, like a 401: a login is told to run mapbox auth login again (also in next_actions); a --token or MAPBOX_ACCESS_TOKEN token is told to add the scope to that token, with mapbox auth whoami as the action.
    • anything else → the existing generic 403 advice.
  • Download confirmation: a binary response written to a file used to finish with no output at all. At a terminal it now prints Wrote application/zip (988165 bytes). to stderr. stdout is unchanged, and --quiet hides it. This applies to every binary command, not just styles download.

Testing

  • cargo fmt, cargo clippy --all-targets -- -D warnings, cargo test pass.
  • Against production:
    • A login from before this change (no styles:download) gets the "log in again" advice; the same token passed through MAPBOX_ACCESS_TOKEN gets "add the scope to that token" instead.
    • After a fresh mapbox auth login, styles download downloads a complete ZIP (566 files: style.json, 561 SVG icons and the style's custom .otf), and prints the confirmation line.
    • At a terminal, the command refuses to print the binary, as static get-image does.

@zmofei
zmofei requested a review from a team as a code owner September 30, 2026 09:51
The operation is now enabled for the CLI. Same upstream revision as
before; the only change is the new operation.
styles:download is registrable now, so login asks for it and
downloadStyleZip leaves UNSUPPORTED_OPERATIONS.

The endpoint also needs account access no token carries. A 403 is read
for which cause it is: missing access says to contact Mapbox, a named
missing scope says to log in again, anything else keeps the old advice.
A redirected download otherwise ends in silence. At a terminal, and not
under --quiet, say what was written and how large it was.
@zmofei
zmofei force-pushed the feat/styles-download branch from e135f62 to e6b91b2 Compare September 30, 2026 10:06
The shared 403 says "prerelease" for every account flag, including ones
that gate special access rather than an early release.
@zmofei zmofei self-assigned this Sep 30, 2026
A token from --token or MAPBOX_ACCESS_TOKEN outranks the login, so
logging in again re-sends the same token and gets the same 403. The
advice now depends on where the token came from, as a 401's does.

@mattpodwysocki mattpodwysocki left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Built and ran the full suite on the actual branch: 517 unit tests plus every integration suite pass, fmt/clippy clean, CI all green.

Traced the new 403 classifier closely, since it is the real logic in this PR. It tells apart three causes: an account-access gate ("contact Mapbox"), a missing scope (parsed out of the real error text and checked against a scope-shape regex, so it never echoes arbitrary server text back into advice), and the generic fallback. Verified the missing-scope path gives different fixes depending on where the token came from, a login versus --token/the environment get genuinely different advice since only a login benefits from running mapbox auth login again. Also checked the terminal-refusal message text and the new docs example against the actual code, they match.

Nothing wrong found. Approving.

@zmofei
zmofei merged commit 96e28c2 into main Oct 1, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants