# Feedback

<a id="post-api-v1-feedback"></a>
#### `POST /api/v1/feedback`

*Send product feedback*

Send one report to the publisher (multipart). Fields: `type` (bug, idea, question), `body` (20-5000 characters), `context` (JSON: page_url, page_title, browser, viewport, dpr, admin_lang, theme, dark_mode, js_errors, net_errors — the page address travels as its path only), `links` (JSON list, at most 5 http(s) addresses), `error_logs` (JSON list of fingerprints from /feedback/error-logs), `shot` (PNG or JPEG, at most 3 MB) with `shot_marks` (JSON, at most 20 arrow / frame / blur marks), `attachments` (at most 5 files, 10 MB each, 16 MB together; extension and content checked) and `lang`. The agent adds its version, PHP versions, operating system, web server and the licence key's last four characters; the operator's user name and e-mail address go as the reporter. Refusals carry the publisher's reason in `details.reason`: 403 FEEDBACK_DISABLED, 403 FEEDBACK_NOT_RECOGNISED, 429 FEEDBACK_TOO_MANY, 422 FEEDBACK_REJECTED, 422 FEEDBACK_SPAM, 413 FEEDBACK_TOO_LARGE, 422 FEEDBACK_ATTACHMENT_REJECTED, 422 FEEDBACK_LINK_REJECTED, 503 FEEDBACK_UNAVAILABLE, 502 FEEDBACK_FAILED.

**Auth:** admin browser session only (the `whost_session` cookie the panel holds); an HMAC-signed request is answered `401 AUTH_FAILED`.

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `attachments` | array<string> | no | — |
| `body` | string | no | default `` |
| `context` | string | no | default `` |
| `error_logs` | string | no | default `` |
| `lang` | string | no | default `` |
| `links` | string | no | default `` |
| `shot` | string | no | — |
| `shot_marks` | string | no | default `` |
| `type` | string | no | default `bug` |

**Request body example:**

```json
{
  "attachments": [
    "string"
  ],
  "body": "",
  "context": "",
  "error_logs": "",
  "lang": "",
  "links": "",
  "shot": "string",
  "shot_marks": "",
  "type": "bug"
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_FeedbackSentData_` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {
    "attachments": 0,
    "error_logs": 0,
    "links": 0,
    "ref": "string",
    "shot": false
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -b "whost_session=$WHOST_SESSION" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/feedback
```

---

<a id="get-api-v1-feedback-error-logs"></a>
#### `GET /api/v1/feedback/error-logs`

*Error records a report may carry*

The agent's ERROR and CRITICAL records of the last 72 hours (agent.log), grouped by fingerprint, newest first, at most 10, masked the way they would travel (account names, domains, addresses, e-mail addresses and credentials replaced). The window sends back the fingerprints the operator keeps; the records are read again from the log on send.

**Auth:** admin browser session only (the `whost_session` cookie the panel holds); an HMAC-signed request is answered `401 AUTH_FAILED`.

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_FeedbackErrorLogsData_` | Successful Response |

**Response example (200):**

```json
{
  "data": {
    "hours": 0,
    "items": [
      "..."
    ]
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X GET \
  -b "whost_session=$WHOST_SESSION" \
  https://your-server:2000/api/v1/feedback/error-logs
```

---

<a id="get-api-v1-feedback-status"></a>
#### `GET /api/v1/feedback/status`

*Feedback window status*

Whether the panel offers the product feedback window, with the caps it applies and the name and address the report is sent as. Offered while the licence is active or in grace, the whitelabel brand is off and the publisher's last answer (refreshed daily, kept 48 hours) says its channel takes reports from this server. An answer older than a day is refreshed in the background.

**Auth:** admin browser session only (the `whost_session` cookie the panel holds); an HMAC-signed request is answered `401 AUTH_FAILED`.

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_FeedbackStatusData_` | Successful Response |

**Response example (200):**

```json
{
  "data": {
    "available": false,
    "checked_at": "...",
    "limits": "...",
    "reason": "open",
    "reporter": "..."
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X GET \
  -b "whost_session=$WHOST_SESSION" \
  https://your-server:2000/api/v1/feedback/status
```

---
