diff --git a/STATUS.md b/STATUS.md index 82c756b8..6eab2a22 100644 --- a/STATUS.md +++ b/STATUS.md @@ -47,6 +47,25 @@ - **Still to prove:** the lost off-site copy alarm (Tester 1's next clean-up window, about 12 October), and the failed-restore hold (needs a scratch off-site store). +## Facebook is live (2026-10-09): the Page can now post in public + +- **The Meta app is switched on.** Until today anything the Page posted was visible only to people with a role + on the app — effectively nobody. It is now **Published**, so posts are public. +- What had been holding it up for a day was the terms page, which did not exist until this morning. I put both + addresses into the app's settings, chose its category, and switched it over. **The app icon turned out not to + be required** — Meta accepted it without one, so that item is off the list. +- **Nothing new was granted.** The app can do exactly what it could do yesterday; going live only changes who + can *see* what it posts. +- **You can start posting whenever you like.** The two texts we parked — the long description and the four + Messenger answers — were waiting on exactly this, and are ready to go out as posts. + +## Website (2026-10-09): the header says the name once, and the footer links look like links + +- The header showed „felhom.eu" twice: once baked into the logo picture and once typed beside it. Now there is + one lockup — the symbol on its own, larger, with the name next to it **in the logo's own lettering**, not a + typeface that merely looks similar. The footer's legal links now match every other link on the site, and no + longer turn purple after you have read them once. + ## Done and still owed (2026-10-09): the published password is dead for Gitea — but it still opens a dozen other things Following up the finding below, I measured what that password actually was. It was **your Gitea admin login**, diff --git a/documentation/audits/facebook-page-details-2026-10-09/E1-meta-app-published.jpg b/documentation/audits/facebook-page-details-2026-10-09/E1-meta-app-published.jpg new file mode 100644 index 00000000..7dd7c7d2 Binary files /dev/null and b/documentation/audits/facebook-page-details-2026-10-09/E1-meta-app-published.jpg differ diff --git a/documentation/backlog/CLOSED-ITEMS.md b/documentation/backlog/CLOSED-ITEMS.md index d3e05520..9f8bccb8 100644 --- a/documentation/backlog/CLOSED-ITEMS.md +++ b/documentation/backlog/CLOSED-ITEMS.md @@ -26,6 +26,16 @@ --- +## 2026-10-09 — the Meta app is Live: the Facebook Page can post in public + +The full text of the row below: `git show 625d38645c:documentation/backlog/OPEN-ITEMS.md`. + +| Row | What | Closed | Evidence | +|---|---|---|---| +| **R-915** | **The Meta app `felhom.eu` was in development mode, so anything it posted was visible only to people with a role on the app.** (P4) | CLOSED 2026-10-09 — the app is **Published**. What it had been waiting for was R-813's Terms of Service URL, which did not exist until the closed-test legal set went live that morning. Filled in Basic settings: **Privacy policy URL** `https://felhom.eu/adatkezeles`, **Terms of Service URL** `https://felhom.eu/feltetelek`, **User data deletion → Data deletion instructions URL** `https://felhom.eu/adatkezeles` (the notice says how: write to `info@felhom.eu`), **Category** „Vállalkozások és oldalak". Meta then reported **„All required app settings are complete"** — the app **icon turned out NOT to be required**, which is worth recording because the original row listed it among the blockers. **Read back from a full page reload, not from the success toast** (Meta's toasts have lied on this Page before): the sidebar badge reads `Published`, the string `Unpublished` is gone, and the page now offers `Unpublish`. No permission was added and no use case changed — `business_management` et al. stay „Ready for testing", which is all a system user needs for the business's own Page. | `audits/facebook-page-details-2026-10-09/E1-meta-app-published.jpg` | + +**Reasoning kept.** Going Live is about *who can see what the app posts*, not about new powers: the system user already had the Page scopes, and nothing was granted here. The app icon, display name and contact e-mail were listed as Live blockers in the original row; only the two URLs and the category actually were. + ## 2026-10-09 — can the business survive losing DooPlex: Gitea + secrets off-site, Gitea and the hub restored into throwaways The full text of every row below: `git show 59f1ad2b86:documentation/backlog/OPEN-ITEMS.md`. diff --git a/documentation/backlog/OPEN-ITEMS.md b/documentation/backlog/OPEN-ITEMS.md index 5df03f23..94152ea4 100644 --- a/documentation/backlog/OPEN-ITEMS.md +++ b/documentation/backlog/OPEN-ITEMS.md @@ -260,22 +260,21 @@ stopping line that lies. | **R-814** | Hub & operator | P4 | `PBS-storage-1` (u629193, box 611421) still `status=active`, 19.9 MB | **VERIFY** (2026-10-03 triage: a July watch row with no id; given R-814. WAITING-ON-OPERATOR — no record found that the box was deleted.) — WAITING-ON-OPERATOR | operator console | Delete the box | operator | | **R-844** | Hub & operator | P4 | **The household's OS-update line exists only on the hub's customer timeline.** 2026-10-04: the box itself has no event surface for agent results (the controller UI shows no timeline), so `os_update_applied` is a hub customer event (info: recorded, never mailed). Its stored text is the hub's English sentence; the hu/en bundle text (`mail.event.os_update_applied`) is used only if it is ever mailed. Fix direction: a controller-side line (the controller already polls the agent's local API) when the box gets a household timeline. `audits/os-guest-lane-2026-10-04/partG/hub-customer-timeline-demo-hp.txt` | **READY — owner: CC** **2026-10-05 (burn-down night): NEEDS A DESIGN** — a household timeline on the box does not exist yet. | — | — | CC | -## Business & legal — 12 rows (P2 4, P3 1, P4 7) +## Business & legal — 11 rows (P2 4, P3 1, P4 6) | ID | Category | Sev | What | State | Blocked on | Next action | Owner | |---|---|---|---|---|---|---|---| | **R-784** | Business & legal | P2 | **[P2-MEDIUM] SparkyFitness's licence forbids commercial use: "may not be used, directly or indirectly, in any product, service … intended for … commercial advantage … without prior written permission from the author" — and Felhom is a paid service that offers it in its catalog.** READ 2026-10-01 (`audits/visitors-2026-10-01/C/C0-license.txt`): a custom licence (GitHub: NOASSERTION), the same at the pinned tag v0.17.3 and at `main`; termination clause 7 ("cease all use"). SparkyFitness was named as wger's replacement for fitness. **Needs (operator):** (A) hide it from new installs (`lifecycle: hidden`) until the author gives written permission, and ask; (B) ask first and keep it offered meanwhile; (C) keep it. Recommended A. If nothing is decided it stays offered. **UPDATE 2026-10-02 — DECIDED (`09` §3 decision 65, option B):** SparkyFitness stays offered; the operator asks the author. The request is drafted (NOT sent): `audits/licences-2026-10-02/EMAIL-DRAFT-sparkyfitness.md` — the author publishes no e-mail; the routes are the project's Discord (private, recommended) or a GitHub Discussion. **Trigger:** no written permission before the first paying customer → `lifecycle: hidden` (a STATUS standing item). **2026-10-08: the public apps page lists SparkyFitness** (Hungarian and English), badged *Korlátozott licenc* / *Restricted licence*, as it lists Tandoor (R-789) — the box offers both today; removing the cards is one small commit if the decision goes that way. | **WAITING-ON-OPERATOR — rank P2-MEDIUM; owner: operator (send the request; the answer)** | — | — | operator | | **R-789** | Business & legal | P2 | **[P2-MEDIUM] Tandoor's licence is AGPL-3.0 WITH the Commons Clause: it forbids selling "a product or service whose value derives, entirely or substantially, from the functionality of the Software" — fees for hosting or support included.** READ 2026-10-02 at 2.6.15 (`audits/licences-2026-10-02/TABLE.md`). Felhom charges for installing and caring for the household's apps; whether that value comes "substantially" from Tandoor is the question. **Needs (operator):** keep (the fee is for the box, not Tandoor), hide for new installs, or ask the authors. Nothing changed meanwhile. **RULED 2026-10-02 afternoon (`09` §3 decision 66):** treated like SparkyFitness — stays offered; the operator asks the authors for written permission; without it before the first paying customer Tandoor is hidden (`lifecycle: hidden`). STATUS "Before the first paying customer". | **WAITING-ON-OPERATOR — rank P2-MEDIUM; owner: operator (the request; trigger: first paying customer)** | — | — | operator | | **R-802** | Business & legal | P2 | **[P2-MEDIUM] A lawyer reviews the non-OSI licence list before the first paying customer.** Operator ruling 2026-10-02 (`09` §3 decision 66): Tandoor (R-789), SparkyFitness (R-784), Emby, n8n, Plex (kept — R-790..R-792), the EE/BUSL parts (R-793), redis 7.4 (R-794); the table is `audits/licences-2026-10-02/TABLE.md`. STATUS "Before the first paying customer". | **WAITING-ON-OPERATOR — rank P2-MEDIUM; owner: operator (trigger: first paying customer)** | — | — | operator | -| **R-813** | Business & legal | P2 | **[P2] The website collects personal data but publishes no privacy notice, no terms and no imprint.** CHECKED 2026-10-03 (read-only): `website/` holds nine Hungarian pages and one English page; none is an ÁSZF, an adatkezelési tájékoztató or an impresszum, and no page links to one (ASCII-fragment search `aszf`, `adatkezel`, `impresszum`, `impressum`, `privacy` over `website/`; positive control: the same search finds `adatkezel` in the contact form). The contact form makes the visitor tick a data-processing consent (`website/kapcsolat.html:123-128`) whose text names no controller, no retention and no rights, and links nowhere. The papers around it — contract, data-processing agreement, billing — are the intention **R-809** in `ROADMAP.md`. **2026-10-08 (website refresh): the English twins are PUBLIC since today** (`felhom.eu/en/…`, operator choice B) — **the legal pages are needed in English too**, or an English line saying the legal texts are Hungarian, linked from every English page. The English contact form translates the consent text as it is. The refresh CUT the FAQ's „önálló modell" (no row backs it, brief Part A) and LEFT the GDPR answer („nem harmadik félnél") for R-900; the English FAQ carries the same answer. | **NARROWED 2026-10-09 — the closed-test set is PUBLISHED.** Live: (`website/adatkezeles.html`) and (`website/feltetelek.html`), Hungarian only, version „Zárt teszt — 1.0 verzió, hatályos: 2026. október 9.” Text of record: `documentation/legal/{adatkezelesi-tajekoztato,feltetelek}-1.0.md`, **derived from the published HTML** so it cannot drift from the page. All 18 pages carry the operator, `info@felhom.eu` and both links in the footer (counted: 18 found = 18 with both links = 18 structurally valid); the English footers say the legal texts are Hungarian, and `site_gates.py` `NO_TWIN` holds the two pages deliberately — an unreviewed English legal text would be worse than an honest pointer. The contact form's consent text was replaced in both languages: the old one claimed „az adatokat harmadik félnek nem adjuk ki” while Resend, Cloudflare and Google carry the message. **Operator rulings 2026-10-09:** no company yet, so the operator is named as a PRIVATE PERSON (Nagyfenyvesi Viktor) with **no postal address and no phone**; publish before the lawyer, because the site was collecting data with no notice at all; and keep three retentions honestly open-ended (website statistics, web server logs, contact messages) rather than promise a date nothing enforces. Four load-bearing claims were MEASURED, not copied from a vendor or a README: zero cookies and no local storage (browser check with a positive control, after the tracker fired; no `Set-Cookie` on any response); the Umami beacon's exact payload (site id, screen, language, title, url, referrer — no visitor identifier); Cloudflare is DNS only (the public A record 37.191.56.193 is not a Cloudflare address); `fsn1` = Falkenstein, Germany. Also measured: `felhom-ep0-copy-gc.timer` is installed and ran successfully (2026-10-09 08:00, exit 0), so the „deleted within 30 days” line is now true where on 2026-10-08 it was written but not switched on. **WHAT REMAINS, which is why this is narrowed and not closed:** the full ÁSZF and the impresszum are still unpublished (they need company data that does not exist); there is no English translation of either legal text; and **no lawyer has reviewed any of it** (R-802). Owner stays operator. | — | Operator: (a) enter the two URLs in the Meta app's Basic settings — this unblocks R-915; (b) when the company exists, commission the lawyer's review (R-802) and the full ÁSZF + impresszum. If nothing is done: the closed-test set stands as published, and the Meta app cannot go Live | operator | +| **R-813** | Business & legal | P2 | **[P2] The website collects personal data but publishes no privacy notice, no terms and no imprint.** CHECKED 2026-10-03 (read-only): `website/` holds nine Hungarian pages and one English page; none is an ÁSZF, an adatkezelési tájékoztató or an impresszum, and no page links to one (ASCII-fragment search `aszf`, `adatkezel`, `impresszum`, `impressum`, `privacy` over `website/`; positive control: the same search finds `adatkezel` in the contact form). The contact form makes the visitor tick a data-processing consent (`website/kapcsolat.html:123-128`) whose text names no controller, no retention and no rights, and links nowhere. The papers around it — contract, data-processing agreement, billing — are the intention **R-809** in `ROADMAP.md`. **2026-10-08 (website refresh): the English twins are PUBLIC since today** (`felhom.eu/en/…`, operator choice B) — **the legal pages are needed in English too**, or an English line saying the legal texts are Hungarian, linked from every English page. The English contact form translates the consent text as it is. The refresh CUT the FAQ's „önálló modell" (no row backs it, brief Part A) and LEFT the GDPR answer („nem harmadik félnél") for R-900; the English FAQ carries the same answer. | **NARROWED 2026-10-09 — the closed-test set is PUBLISHED.** Live: (`website/adatkezeles.html`) and (`website/feltetelek.html`), Hungarian only, version „Zárt teszt — 1.0 verzió, hatályos: 2026. október 9.” Text of record: `documentation/legal/{adatkezelesi-tajekoztato,feltetelek}-1.0.md`, **derived from the published HTML** so it cannot drift from the page. All 18 pages carry the operator, `info@felhom.eu` and both links in the footer (counted: 18 found = 18 with both links = 18 structurally valid); the English footers say the legal texts are Hungarian, and `site_gates.py` `NO_TWIN` holds the two pages deliberately — an unreviewed English legal text would be worse than an honest pointer. The contact form's consent text was replaced in both languages: the old one claimed „az adatokat harmadik félnek nem adjuk ki” while Resend, Cloudflare and Google carry the message. **Operator rulings 2026-10-09:** no company yet, so the operator is named as a PRIVATE PERSON (Nagyfenyvesi Viktor) with **no postal address and no phone**; publish before the lawyer, because the site was collecting data with no notice at all; and keep three retentions honestly open-ended (website statistics, web server logs, contact messages) rather than promise a date nothing enforces. Four load-bearing claims were MEASURED, not copied from a vendor or a README: zero cookies and no local storage (browser check with a positive control, after the tracker fired; no `Set-Cookie` on any response); the Umami beacon's exact payload (site id, screen, language, title, url, referrer — no visitor identifier); Cloudflare is DNS only (the public A record 37.191.56.193 is not a Cloudflare address); `fsn1` = Falkenstein, Germany. Also measured: `felhom-ep0-copy-gc.timer` is installed and ran successfully (2026-10-09 08:00, exit 0), so the „deleted within 30 days” line is now true where on 2026-10-08 it was written but not switched on. **WHAT REMAINS, which is why this is narrowed and not closed:** the full ÁSZF and the impresszum are still unpublished (they need company data that does not exist); there is no English translation of either legal text; and **no lawyer has reviewed any of it** (R-802). Owner stays operator. | — | **(a) DONE 2026-10-09** — the two URLs are in the Meta app's Basic settings and the app is **Live** (R-915 closed). **(b)** when the company exists, commission the lawyer's review (R-802) and the full ÁSZF + impresszum. If nothing is done: the closed-test set stands as published and unreviewed | operator | | **R-89** | Business & legal | P4 | Retention as a per-customer **commercial** policy on the hub | READY (increment 2) | — | Policy object + reconciler → ep0 prune job; keep box tokens write-only | CC | | **R-794** | Business & legal | P4 | **[P3-LOW] redis 7.4 (RSALv2 / SSPL, not OSI) runs as a private cache in seven apps: dawarich, docmost, immich, nextcloud, outline, paperless-ngx, romm.** READ 2026-10-02 (`audits/licences-2026-10-02/TABLE.md`). Read as permitted (a private cache only its app uses is not Redis offered as a service — inferred). Valkey (BSD-3) or redis 8 (AGPL option) removes the question. **Needs:** a ladder step per app to valkey or redis 8, through the harness — no hurry. | **READY — rank P3-LOW; owner: CC** **Re-ranked 2026-10-03: P3→P4: the row itself says no hurry; usage read as permitted.** | — | — | CC | | **R-914** | Business & legal | P4 | **Write the Felhom Facebook Page skill from the spike's findings.** Spike 2026-10-08 (`audits/SPIKE-facebook-page-api-2026-10-08.md`): key valid, never expires; the Page (`1360018983863273`) is reached with CREATE_CONTENT/MODERATE/ANALYZE; a scheduled text post and a scheduled photo were created, read back byte-equal and deleted (removal proven). Probe `scripts/facebook/fb_probe.py`. Gap to close in the skill: a scheduled photo's publish state was not read (no `post_id` returned). **2026-10-08 (Page pictures task) — two more for the skill:** (1) **the removal proof was not a proof**: the text post's after-DELETE answer was (#10) „does not exist, cannot be loaded due to missing permission…" — that message also means a permission gap. The skill proves removal by listing the Page's scheduled posts before and after the delete (present, then absent); the operator's Planner view on 2026-10-08 showed nothing on 15 October (a different channel, by eye). (2) **pictures by API** (READ, developers.facebook.com/docs/graph-api/reference/page/picture and …/reference/page/): `POST /{page}/picture` needs the `MANAGE` task, which the robot does not have (measured task list); the cover is `POST /{page}` `cover=`, „only by the Page Admin or Page Editor with `EDIT_PROFILE`" + `business_management`. Neither names `pages_manage_metadata`. Today the pictures are uploaded by hand (`marketing/facebook/README.md`). | **READY — owner: CC** | — | Write the skill (drafts scheduled for operator review by default); read a scheduled photo back through the Page's scheduled-post listing | CC | -| **R-915** | Business & legal | P4 | **The Meta app `felhom.eu` is in development mode, so posts it makes are seen only by people with a role on the app.** READ 2026-10-08 (Meta docs, cited in the spike); not measured. MEASURED: development mode does not refuse posting (both test writes HTTP 200). Live needs display name, contact e-mail, a Terms of Service URL, an app icon, a category and the app purpose (privacy-policy and data-deletion URLs listed beside them). The robot's Page assignment, missing at first, was done by the operator the same day. | **WAITING-ON-OPERATOR** | R-813 — **UNBLOCKED 2026-10-09**: the Terms of Service URL now exists | Operator, one click job: Meta app → Basic settings → **Privacy Policy URL** = `https://felhom.eu/adatkezeles`, **Terms of Service URL** = `https://felhom.eu/feltetelek`. The Live switch stays a separate operator decision. If nothing is done: posts stay invisible to the public | operator | | **R-916** | Business & legal | P4 | **The logo has no usable vector master: `website/assets/logo.svg` sets „felhom.eu" as live text in the fonts „M+ 2c" and „Vremena Grotesk", which DooPlex does not have, so every renderer here draws other letters.** SEEN 2026-10-08 (Facebook pictures task): librsvg drew the lettering in DejaVu; `fc-match` resolves the family to DejaVu Sans. The PNG (645 x 408) is the only faithful copy, which caps every picture made from it at about that size (`marketing/facebook/README.md`). | **WAITING-ON-OPERATOR** | the machine with the fonts | In Inkscape on that machine: select the lettering → Path → Object to Path → save as `website/assets/logo-master.svg`; then `marketing/facebook/build.py` can use it. If nothing is done: the PNG stays the master; larger prints will be soft | operator | -| **R-917** | Business & legal | P4 | **`COPY.md` §2, the Page's longer description (867 characters), has nowhere to go: Facebook's current Pages experience has no long-description field at all.** FOUND 2026-10-08 (Page setup task, `audits/facebook-page-setup-2026-10-08/`). Looked in four places, all on the live Page as its admin: the Page's „Névjegy" tab (Rövid áttekintés / Személyes adatok / Részletek — only a 255-character „Bemutatkozás" and the pinned category), Business Suite's „Oldal módosítása" dialog (profile picture, cover, Bemutatkozás, category, phone, e-mail, address, website, social links — and nothing else), Facebook settings → „Oldal adatai" (redirects to the same Névjegy tab) and settings → „Oldal beállítása" (name, access, type, history, status, recommendation, messaging, data sharing). MEASURED by Graph with the Page token: `description`, `general_info` and `bio` all read `null`. Writing `description` by API would need `pages_manage_metadata`; the robot key's scopes are `read_insights, pages_show_list, business_management, pages_read_engagement, pages_read_user_content, pages_manage_posts, pages_manage_engagement, public_profile`, and the task's fences forbid adding a permission. So §2 is written, reviewed and unplaceable. **Options for the operator:** (a) leave §2 unused and let the 99-character intro plus the website carry it; (b) shorten §2 to ≤ 255 characters and make it the „Bemutatkozás" instead of §1 — but §1 was written for exactly that slot, so this is really „rewrite one of the two"; (c) publish §2 as the Page's first pinned post once the app is Live (R-915), which is where a long text actually gets read; (d) ask Meta support whether the field still exists for this Page type. Recommended (c) — the text reads like a post already. | **DEFERRED — operator chose (c) on 2026-10-09:** park the text and publish it as a post once posting starts. Not a defect, and not waiting on CC | posting starts — which waits on R-915 (the Live switch) | When posting starts: publish `COPY.md` §2 (the longer description) as the first pinned post. If nothing is done: the text stays in `COPY.md` unused, which the operator has accepted | operator | +| **R-917** | Business & legal | P4 | **`COPY.md` §2, the Page's longer description (867 characters), has nowhere to go: Facebook's current Pages experience has no long-description field at all.** FOUND 2026-10-08 (Page setup task, `audits/facebook-page-setup-2026-10-08/`). Looked in four places, all on the live Page as its admin: the Page's „Névjegy" tab (Rövid áttekintés / Személyes adatok / Részletek — only a 255-character „Bemutatkozás" and the pinned category), Business Suite's „Oldal módosítása" dialog (profile picture, cover, Bemutatkozás, category, phone, e-mail, address, website, social links — and nothing else), Facebook settings → „Oldal adatai" (redirects to the same Névjegy tab) and settings → „Oldal beállítása" (name, access, type, history, status, recommendation, messaging, data sharing). MEASURED by Graph with the Page token: `description`, `general_info` and `bio` all read `null`. Writing `description` by API would need `pages_manage_metadata`; the robot key's scopes are `read_insights, pages_show_list, business_management, pages_read_engagement, pages_read_user_content, pages_manage_posts, pages_manage_engagement, public_profile`, and the task's fences forbid adding a permission. So §2 is written, reviewed and unplaceable. **Options for the operator:** (a) leave §2 unused and let the 99-character intro plus the website carry it; (b) shorten §2 to ≤ 255 characters and make it the „Bemutatkozás" instead of §1 — but §1 was written for exactly that slot, so this is really „rewrite one of the two"; (c) publish §2 as the Page's first pinned post once the app is Live (R-915), which is where a long text actually gets read; (d) ask Meta support whether the field still exists for this Page type. Recommended (c) — the text reads like a post already. | **DEFERRED — operator chose (c) on 2026-10-09:** park the text and publish it as a post once posting starts. Not a defect, and not waiting on CC | nothing — **UNBLOCKED 2026-10-09**: R-915 is closed, the app is Live, so posting can start whenever the operator wants | When posting starts: publish `COPY.md` §2 (the longer description) as the first pinned post. If nothing is done: the text stays in `COPY.md` unused, which the operator has accepted | operator | | **R-919** | Business & legal | P3 | **On a phone the Facebook Page cuts the left edge of the cover: the „s” of „saját szabályaid” and the „f” of „felhom.eu” are gone.** MEASURED 2026-10-08 on the live Page in Chrome DevTools device mode, Pixel 9 (412 × 924, mobile user agent, after a reload so Facebook serves the mobile bundle): `audits/facebook-page-setup-2026-10-08/C2-phone-headline-cut-closeup.png`. The mobile Page header is **412 × 274 = 1,504:1**, so Facebook keeps our cover's full height and shows only the centre **938 px of its 1640 px width (57,2 %)** — **351 px cut from each side**. `marketing/facebook/build.py` builds to a safe area of the centre **1028 × 544** (306 px clear of each edge), which is **45 px wider per side than the phone actually shows**; the light text in `out/cover-c.png` runs from x 333 to x 997, and the left crop edge is x 351, so the first **18 px** of the text are cut. Covers A and B are built from the same safe area and will have the same edge. Two further facts this measurement establishes: **Meta's own help page is wrong about its own rendering** — it states the mobile cover is 2,4:1 where the Page header measures 1,504:1 — and the mobile profile circle is far bigger than assumed (172 px, centred, overlapping the bottom 112 px of the 274 px cover, i.e. source x 637–1030 × y 369–624 is hidden). Not re-cropped on Facebook, per the task's fence. **-- 2026-10-09, FIXED in the build:** `marketing/facebook/build.py` now takes the phone view from the measurement (`PHONE_HDR = (412, 274)` -> the centre 938 px), so SAFE is (391, 40)-(1249, 584) and the phone profile circle is the measured CENTRED box (637, 369, 393) rather than a left-anchored one. Every cover is drawn in a derived `BAND` (408, 48)-(1249, 340), and a `cap` check holds each headline's capital at >= 4 % of the cover height. The red-proof runs on EVERY build (`control_old_window`): it draws the headline where the old 640 x 360 assumption put it, x 328, and the check must reject it -- the phone's crop edge is x 351, so 23 px were cut. Against the three covers as committed at `a76207945e` the new check convicted 3 of 3 (A 23/22 px over the left/right edges, B 63/58 px plus 1017 content pixels under the phone circle, C 63/82 px plus 1778). The profile pictures are untouched -- sha256 identical before and after. **-- 2026-10-09 (operator refinements, same day):** the profile picture now carries the logo MARK only (the lettering was unreadable at 176 px; the mark grew 69 % -> 76 % of the circle, canvas 932 -> 648), and the covers set the headline the way `site.css` sets `.page-index .hero-text h1` (Bold 700, letter-spacing -0.03em, not ExtraBold 800 untracked) with „felhom.eu” drawn from the logo's OWN lettering instead of typed. No geometry changed; every R-919 check and the red-proof stand. **-- 2026-10-09 (second measurement):** a phone has TWO views and they disagree. SIGNED IN the sides are cut (confirmed on the operator's REAL phone, Chrome/Android: the window solves to x 351..1298 against the emulator's 351..1289 - the left edge to the pixel). SIGNED OUT the FULL width is shown but the cover is top-anchored and only the top 525 px survives (the bottom 99 px is cut; the file's blue top rule is still visible, which is how the side was established), with a much bigger, higher circle at x 486..1150 from y 232. `build.py` now carries both views, models the circles as DISCS rather than rectangles running to the bottom, and splits the artwork into a READ layer (must survive every view) and a DECOR layer (may be cropped or covered; the build reports the cost - B 39 %, C 62 %). The two-view geometry convicted all three then-current covers before the redraw (A 908 px under a circle, B 1715, C 1962). Covers redrawn: C is the operator's laptop idea with the dashboard at 640 px (was 370), B's motif grown to match. **-- 2026-10-09 (the APP measured):** the operator checked the live Page in Facebook Lite and in Chrome on his phone. Solved against the laptop frame, both give a visible window of x 349..1290 / 349..1291 - the LITE APP CROPS EXACTLY LIKE SIGNED-IN MOBILE WEB, and both agree with the emulator's 351..1289. Their circle is at x 645..1021 from y 451, LOWER than the emulator's 369, so that figure was pessimistic rather than wrong. Five views measured; the signed-out one stays the binding constraint. Cover C redrawn to the operator's layout (wordmark 88 px on top, gap, catchphrase) - one line, not his two, because two measured 392 text pixels behind the signed-out circle („saját szabályaid” read „saját szab”) and sizing them to fit drops the capital to the 25 px floor. | **VERIFY -- rebuilt on `main` 2026-10-09. The app IS now measured and the cover renders correctly there; what is left is the operator's look at the NEW cover in the app after uploading it.** | — | Operator: upload the rebuilt cover-c (and the profile picture if not already), then confirm in the Facebook app that the wordmark and the catchphrase are whole. Close on that word | CC | -| **R-920** | Business & legal | P4 | **The Messenger „Gyakori kérdések" automation does not exist for this Page, so `COPY.md` §5 — four questions with answers condensed from `gyik.html` — has nowhere to go.** FOUND 2026-10-09 (Page details task, `audits/facebook-page-details-2026-10-09/`). SEARCHED, not assumed absent: the create-automation catalogue („Az összes automatizálás") holds exactly THREE templates — Automatikus válasz, Távolléti üzenet, A megválaszolatlan üzenetek azonosítása (`B5-no-faq-template-all-three.jpg`); the template search for „kérdés" answers **„Nincs a keresésnek megfelelő automatizálási sablon."** while the POSITIVE CONTROL „üzenet" returns two, so the search works and the term genuinely misses; the existing instant-reply automation carries only channel, message and media — no FAQ and no quick replies; and the business-portfolio settings have no messaging/FAQ entry. The copy is written, sourced line by line to `gyik.html` and committed as `marketing/facebook/COPY.md` §5, ready to paste unchanged the day the feature appears. **Same shape as R-917** (§2 has nowhere to go), and the same cause: Meta removed a Page field this project had planned copy for. **Options for the operator:** (a) leave §5 unused until Meta brings the feature back; (b) fold the four answers into the Messenger welcome message (§3) — it holds 500 characters and today uses 120, so one or two would fit, not four; (c) publish them as a pinned FAQ post once the app is Live (R-915); (d) ask Meta support whether the FAQ automation still exists for this Page type. Recommended (a) with (c) later — the welcome message stays short, and the website's own `gyik.html` already answers these. | **DEFERRED — operator chose (c) on 2026-10-09:** park the text and publish it as a post once posting starts. Not a defect, and not waiting on CC | posting starts — which waits on R-915 (the Live switch) | When posting starts: publish `COPY.md` §5 (the four Messenger FAQ answers) as one later post. If nothing is done: the text stays in `COPY.md` unused, which the operator has accepted | operator | +| **R-920** | Business & legal | P4 | **The Messenger „Gyakori kérdések" automation does not exist for this Page, so `COPY.md` §5 — four questions with answers condensed from `gyik.html` — has nowhere to go.** FOUND 2026-10-09 (Page details task, `audits/facebook-page-details-2026-10-09/`). SEARCHED, not assumed absent: the create-automation catalogue („Az összes automatizálás") holds exactly THREE templates — Automatikus válasz, Távolléti üzenet, A megválaszolatlan üzenetek azonosítása (`B5-no-faq-template-all-three.jpg`); the template search for „kérdés" answers **„Nincs a keresésnek megfelelő automatizálási sablon."** while the POSITIVE CONTROL „üzenet" returns two, so the search works and the term genuinely misses; the existing instant-reply automation carries only channel, message and media — no FAQ and no quick replies; and the business-portfolio settings have no messaging/FAQ entry. The copy is written, sourced line by line to `gyik.html` and committed as `marketing/facebook/COPY.md` §5, ready to paste unchanged the day the feature appears. **Same shape as R-917** (§2 has nowhere to go), and the same cause: Meta removed a Page field this project had planned copy for. **Options for the operator:** (a) leave §5 unused until Meta brings the feature back; (b) fold the four answers into the Messenger welcome message (§3) — it holds 500 characters and today uses 120, so one or two would fit, not four; (c) publish them as a pinned FAQ post once the app is Live (R-915); (d) ask Meta support whether the FAQ automation still exists for this Page type. Recommended (a) with (c) later — the welcome message stays short, and the website's own `gyik.html` already answers these. | **DEFERRED — operator chose (c) on 2026-10-09:** park the text and publish it as a post once posting starts. Not a defect, and not waiting on CC | nothing — **UNBLOCKED 2026-10-09**: R-915 is closed, the app is Live, so posting can start whenever the operator wants | When posting starts: publish `COPY.md` §5 (the four Messenger FAQ answers) as one later post. If nothing is done: the text stays in `COPY.md` unused, which the operator has accepted | operator | ## Process & tooling — 23 rows (P3 3, P4 20) diff --git a/marketing/CHANGELOG.md b/marketing/CHANGELOG.md index ca19ff22..b01ecfeb 100644 --- a/marketing/CHANGELOG.md +++ b/marketing/CHANGELOG.md @@ -1,5 +1,45 @@ # marketing — CHANGELOG +## facebook — the Meta app is LIVE; the Page can post in public (2026-10-09) + +R-915 is closed. What it had waited on for a day was R-813's Terms of Service URL, which did not +exist until the closed-test legal set went live this morning. + +- **Filled in the app's Basic settings:** Privacy policy URL `https://felhom.eu/adatkezeles`, + Terms of Service URL `https://felhom.eu/feltetelek`, User data deletion → *Data deletion + instructions URL* `https://felhom.eu/adatkezeles` (the notice says how: write to `info@felhom.eu`), + and Category „Vállalkozások és oldalak" — the app exists to manage the Page. +- **The app icon was NOT required**, although the original row listed it among the blockers. Meta + answered „All required app settings are complete" with the icon still empty. Recorded because the + row would otherwise keep sending the next session to upload one. (It cannot be uploaded from here + anyway — the icon control creates its file input only on click, and clicking opens a native dialog + the browser tooling cannot drive.) +- **Published, and read back from a full page reload rather than the success toast**, because Meta's + toasts have lied on this Page before: the badge reads `Published`, the string `Unpublished` is + gone, and the page now offers `Unpublish`. +- **Nothing was granted.** No permission added, no use case changed; the scopes stay + „Ready for testing", which is all a system user needs for the business's own Page. Going Live + changes **who can see what the app posts**, not what it may do. +- **R-917 and R-920 are unblocked** by this: both were waiting for posting to start. The long + description (§2) and the four Messenger FAQ answers (§5) can be published as posts whenever the + operator wants. + +## website — one brand lockup in the header, footer links that look like links (2026-10-09) + +- The header showed the name twice: `logo.png` carries its own „felhom.eu" lettering under the mark, + and a typed `` repeated it beside the image — which also forced the mark + down to 40 px. Now the mark alone (the vector `logo_notext.svg`, 54 px) with the brand's OWN + lettering next to it, cropped from `logo.png` into `assets/logo-wordmark.png`. +- **Why the name is artwork and not text:** that face is „M+ 2c"/„Vremena Grotesk" (R-916), which + nothing here has, and the site deliberately loads **no external font** — the privacy notice + published the same morning states exactly that, so adding Google Fonts to match a logo would have + made a published claim false. The Facebook covers already draw the wordmark from the logo for the + same reason. The white/blue split is in the artwork itself. +- Footer links were unstyled, so the browser painted them default blue and **purple once visited**. + They now follow the site's own convention: `--blue-bright`, no underline, underline on hover, with + **`:visited` pinned to the same colour** — a legal link that changes colour after one read looks + like it stopped working. + ## facebook — Page details: categories added, contact already set, Messenger FAQ refused (2026-10-09) Second task of the day, after the cover work: the Page's details box, the Messenger FAQ and the link