diff --git a/marketing/facebook/TASK-page-setup-windows.md b/marketing/facebook/TASK-page-setup-windows.md new file mode 100644 index 00000000..0c5e007d --- /dev/null +++ b/marketing/facebook/TASK-page-setup-windows.md @@ -0,0 +1,127 @@ +# Claude Code Prompt (Windows, with Claude in Chrome): finish the Felhom.eu Facebook Page setup + +--- + +## For the operator — what this does, in one page + +**What is true today.** The robot key works and reaches the Page. You uploaded the new profile picture (dark) +and cover C. The Page still shows the OLD intro text. The username, the action button, the details text and +the Messenger welcome message are not set yet. + +**What this run does.** Claude Code on your Windows PC uses your Chrome (Claude in Chrome) to: +1. read Meta's own picture-size page, which DooPlex could not open; +2. check the new pictures on the live Page, at computer width and at phone width; +3. paste the texts from `marketing/facebook/COPY.md`: the intro, the details, the Messenger welcome; +4. set the action button to the website; +5. set the Page username — **only after you say which name** (it asks you first). + +**What you will be asked to do.** One answer: the username (proposed: `felhom`). Maybe a permission click in +Chrome for facebook.com. + +**What is not affected.** No post. No ad, no boost, no money, no Meta Verified. The app stays in development +mode. No box, no customer, no hub. + +--- + +## 0. Task class & scope + +- [x] **Operational** — Page settings by hand, through the operator's own browser. No product code. +- **Repos touched:** `felhom.eu` only (`marketing/`, `documentation/audits/`, register rows R-914/R-915/R-916 + only if a fact changes). + +## 1. Confirmed baselines + +| Repo | `main` @ commit | → | +|---|---|---| +| felhom.eu | `0fd4c818` (or later — pull first; the clean-tree gate applies) | commit to `main` directly | + +## 2. Where things are + +- Page: Felhom.eu, Graph ID `1360018983863273`, browser address `https://www.facebook.com/profile.php?id=61595336666018`. +- Business portfolio `4713349378884589`; Meta app `felhom.eu` (`2273465403490709`), **development mode — leave it**. +- Texts: `marketing/facebook/COPY.md` (§1 intro, §2 details, §3 Messenger welcome, §4 posts — NOT this task). +- Pictures and their checks: `marketing/facebook/README.md`, `out/preview.html`. +- What was proven so far: `documentation/audits/SPIKE-facebook-page-api-2026-10-08.md`, + `REPORT-facebook-page-api.md`, `REPORT-facebook-page-pictures.md`. +- Read-only probe: `scripts/facebook/fb_probe.py` (token from the credentials file; Bearer header; redacts). + +## 3. Fences — read before any click + +1. **Read-only on Facebook except the five edits in §5.** No post, no story, no reel, no comment, no reply, no + message sent, no like, no follow, no invite. If a dialog offers „share to feed / Megosztás a hírfolyamban", + turn it **off**. +2. **No money and nothing that can cost money:** no „Hirdess" / Boost / Ads Manager, no Meta Verified, no + payment settings, no „Bevételszerzés". +3. **No change to the Meta app or the business:** do not switch the app to Live (R-915 needs a Terms of Service + URL first), no new permission, no new token, no system-user change, no Page role change. +4. **Secrets:** never print, screenshot or commit `FACEBOOK_API` or any token. No screenshot of the + credentials file, Business Suite's token pages, the Messenger inbox or the operator's personal profile. + Screenshots of the Page itself and of the setting being changed are fine. +5. **Ask, do not guess:** the username is a public, hard-to-change name — ask the operator first. Any field not + listed in §5: leave it. +6. **No dialogs you cannot see the end of:** avoid buttons that may raise a browser `confirm()`; if Chrome stops + responding, ask the operator to close the dialog. +7. **Standing rules apply** (workspace `CLAUDE.md`): never test and commit in one command; an absent line is not + proof — verify each change with a positive read-back from a **different channel** than the one that made it; + evidence is saved at the end of each phase. +8. **Hungarian text:** paste exactly from `COPY.md`; compare by UTF-8 hex, not by eye. Search Hungarian with + ASCII fragments, with a positive and a negative control. +9. Commit to `main`; no branch; **no „Co-Authored-By" line.** Stage explicit paths only (never `git add -A`). + +## 4. Phase A — read Meta's own size page (first-hand) + +Open `https://www.facebook.com/help/125379114252045` (Hungarian title: „A Facebook-oldalak profilképének és +borítóképének méretei"). Quote every pixel figure verbatim (cover on computer, on phone, minimum; profile +picture sizes). Save the quote to `documentation/audits/facebook-page-setup-2026-10-08/A-meta-sizes.md` with the +URL and the time. + +Then compare with `marketing/facebook/README.md` „Sizes used" (820 x 312 computer, 640 x 360 phone, profile ~176 px). +- Same → change that section's grade from „READ, second-hand" to „READ, Meta's help page" with the quote's path. +- Different → record the difference; do NOT rebuild here; say in the report whether the pictures are still safe + (the safe area is the centre 1028 x 544 px of 1640 x 624). + +## 5. Phase B — the Page edits (each one: before screenshot → edit → after read-back) + +| # | Edit | Source | Read-back from a different channel | +|---|---|---|---| +| B1 | Intro / Bemutatkozás → replace with `COPY.md` §1 | §1 block (99 characters) | `fb_probe.py read` → `C1-page.json` `about` hex == §1 hex | +| B2 | About → details / Részletek → `COPY.md` §2 | §2 block | the Page's „Névjegy" tab, page text copied out, hex compare | +| B3 | Action button → „Weboldal" / Website → `https://felhom.eu` | — | the Page's public view: the button's link target | +| B4 | Messenger welcome message → `COPY.md` §3, turned on | §3 block | the setting's saved text read back, hex compare | +| B5 | Username → **the name the operator gives** | ask first | the Page address `facebook.com/` loads the Page | + +For B1 the probe is run with its own evidence directory, so the spike's evidence is not overwritten: +`python scripts/facebook/fb_probe.py -v --evidence documentation/audits/facebook-page-setup-2026-10-08/probe read` +(use `py` if `python` is not on PATH). Read `rc`; a non-zero rc is reported, not retried with other settings. +Check the saved files hold no token: plant `EAAfakeprobe` in a scratch file there, grep for `EAA` (expect 1), +delete it, grep again (expect 0). + +If a field's limit refuses a text: stop that edit, quote Meta's message, report it. Do not shorten Hungarian copy +yourself — the operator decides. + +## 6. Phase C — the pictures on the live Page + +With `resize_window`: the Page at 1440 px wide and at 390 px wide (phone). Screenshot each into the evidence +directory. Check and report: the profile circle does not cut the logo; the cover headline and „felhom.eu" are +whole at both widths; the profile circle does not cover cover text. A cut is a finding — report it with the +screenshot; do not re-crop on Facebook. + +## 7. Documentation and finish + +1. Evidence: `documentation/audits/facebook-page-setup-2026-10-08/` (A quote, B before/after screenshots and + read-backs, C screenshots, probe JSON). No token, no personal data. +2. `marketing/CHANGELOG.md`: one entry. `marketing/facebook/README.md`: the sizes grade (Phase A). +3. `REPORT-facebook-page-setup.md` (own file; do not touch the shared `REPORT.md`). +4. Register: no new row unless something is refused or broken. R-915 stays open (Live mode). +5. Run `python scripts/repo_gates.py --fast`, read `rc`, then commit and push. Confirm the CI job for your + commit by `head_sha` (CLAUDE.md recipe), quote its id and conclusion. + +## 8. Final report + +1. Baseline and pushed commit. +2. Phase A: Meta's figures quoted, and same/different from ours. +3. Each of B1–B5: done / refused / skipped, with the read-back result (hex equal yes/no). +4. Phase C: the four checks, with screenshot names. +5. Secret scan counts (with the control, after removing it). +6. What the operator still does: post §4 after Live (R-915); the vector logo (R-916). +7. Teardown: nothing posted; no app or business change; nothing on any host or the hub.