diff --git a/CONTEXT.md b/CONTEXT.md index 211cdf55..888b0f46 100644 --- a/CONTEXT.md +++ b/CONTEXT.md @@ -22,8 +22,8 @@ > DooPlex; the Page token is derived at run time and never stored; no third-party SDK or MCP server touches it > (operator ruling 2026-10-08). Posts go out **scheduled, for operator review, by default**. Ads are a separate app, > not built. No architecture document covers this and none should: it is a business tool, not part of the product. -> Measured: token valid, `expires_at 0`, but `/me/accounts` empty — waits on the operator's asset click (R-915); -> the skill is R-914. +> Measured: token valid, `expires_at 0`; Page `1360018983863273` reached; scheduled post + photo created, read back +> byte-equal, deleted. Public posting waits on Live mode (R-915, needs the ToS URL of R-813); the skill is R-914. > **2026-10-08 (evening) — the decision sheet D1–D10 built on main, unreleased (`09` §3 185–194).** Controller (`3f84f82`): > operator actions (`internal/report/opactions.go`, closed list), dashboard sessions on disk as sha256 + password diff --git a/REPORT-facebook-page-api.md b/REPORT-facebook-page-api.md index a6607526..08798524 100644 --- a/REPORT-facebook-page-api.md +++ b/REPORT-facebook-page-api.md @@ -4,47 +4,44 @@ Own file, not `REPORT.md`: parallel sessions share this clone (`CLAUDE.md` workf ## For the operator -- The robot key works. It never runs out. -- The robot sees **no Page**. So the run stopped before any post. Nothing was posted. Nothing was deleted. -- **You do one click:** Meta Business Suite → Settings → Users → System users → `felhom-cc` → Assign assets → - Pages → Felhom.eu → Full control. If Felhom.eu is not in the list: Settings → Accounts → Pages → add it first. -- After that, tell Claude to re-run the probe. If you do nothing: Claude cannot post. Nothing else breaks. -- Later, before real public posts: switch the Meta app to „Live". It needs a Terms of Service web address. +- Yes. Claude can make posts on the Felhom.eu Page. +- The key works. It never runs out. +- Test: one scheduled text post and one scheduled photo. The Hungarian accents came back exact. Both are deleted. +- **Later, before real public posts:** switch the Meta app to „Live". It needs a Terms of Service web address. + If you do nothing: only people with a role on the app see the posts. +- Optional check: Meta Business Suite → Planner should show no scheduled post. ## Results | Scenario | Result | Evidence | |---|---|---| -| A — key valid, long-lived | PASS: `SYSTEM_USER`, app 2273465403490709, `is_valid true`, `expires_at 0`, `data_access_expires_at 0` | `A1-debug-token.json` | -| B — reaches the Page | **FAIL: `/me/accounts` = `{"data": []}`**; robot = `felhom-cc` (122094150717513084) | `B1`, `B2` | -| C — read calls | not run (no Page token) | — | -| D — scheduled text post | not run (§8: no Page → stop) | — | -| E — scheduled photo | not run | — | -| F — headers | `facebook-api-version: v26.0`; `x-business-use-case-usage` recorded | `F1-headers.json` | -| F — docs (read) | dev-mode posts seen only by role users; own-Page use needs no App Review (Standard Access); Live needs ToS URL, icon, category, contact e-mail, app purpose | spike doc, with URLs | +| A — key | PASS: `SYSTEM_USER`, app 2273465403490709, valid, `expires_at 0` | `A1-debug-token.json` | +| B — Page | first run FAIL (no Page assigned); after the operator's click PASS: Felhom.eu `1360018983863273`, `CREATE_CONTENT` + `MODERATE` + `ANALYZE`; Page token `PAGE`, `expires_at 0` | `B2`, `B3` | +| C — reads | PASS: Page fields, feed (1 post), 3 insights metrics alive on v26.0 | `C1`–`C3` | +| D — text post | PASS: unpublished, schedule equal, hex equal, deleted, gone | `write-test/D*` | +| E — photo | PASS: only a photo `id` returned (no `post_id`); caption hex equal; DELETE on the photo id; gone. **Gap:** its publish state could not be read | `write-test/E*` | +| F — mode | no refusal in development mode (measured); dev-mode posts seen only by role users (read); Live needs ToS URL etc. (read) | spike doc | -Read run twice; same result. Exit code 4 both times (B failed) — the brief's green gate „exit 0 on read" is not -met, because of the missing Page, not the script. +- **Secret scan:** with the planted `EAAfakeprobe` control: 1 hit; after removing it: 0. No `access_token` key, no + `access_token=` URL in the evidence. Staged-diff scan: the one hit is the test file's fake token. +- **Accent round-trip:** D yes (message hex equal). E yes (photo caption hex equal). +- **Teardown — Facebook:** created and deleted: text `1360018983863273_122096071749511222` (run 1), + text `1360018983863273_122096072277511222` and photo `122096072325511222` (run 2). The GET after each DELETE: + text posts (#10) „Object does not exist, cannot be loaded due to missing permission…"; photo (#100/33) + „Unsupported get request. Object with ID '122096072325511222' does not exist…". **Host:** nothing provisioned. + **Hub:** nothing created. +- **Register:** 136 → 138; opened R-914 (CC, READY), R-915 (operator, Live mode). Closed 0. +- `unproven.py --summary`: not walked 35 of 55 (unchanged). -- **Secret scan:** with the planted `EAAfakeprobe` control: 1 hit. After removing it: 0. Token tail search over - evidence, spike doc and script: 0. -- **Accent round-trip:** not measured (D/E not run). -- **Teardown:** Facebook — no post created, none to delete. Host — nothing provisioned. Hub — nothing created. -- **Register:** 136 before → 138 after; opened R-914 (skill, CC, BLOCKED on R-915), R-915 (operator, the asset - click + Live). Closed 0. +## Fixed without a row -## Files - -`scripts/facebook/fb_probe.py`, `scripts/facebook/test_fb_probe.py`, `scripts/CHANGELOG.md`, -`documentation/audits/SPIKE-facebook-page-api-2026-10-08.md`, `documentation/audits/facebook-page-api-2026-10-08/`, -`documentation/backlog/OPEN-ITEMS.md`, `CONTEXT.md`, `STATUS.md`, this report. +- The probe proved removal on code 100 only; Meta answers a deleted post with code 10. Run 1 stopped (exit 7) on a + post that was in fact gone (same token read it 200 just before). `gone_error()` + 4 tests; run 2 passed. ## Observations -- The granular scopes carry no `target_ids`, and `read_insights` is in `scopes` but not in `granular_scopes` — - NOT-A-FINDING: recorded in the spike table; re-check after R-915. -- Which of the two clicks is missing (asset assignment vs Page not in the portfolio) was not measured: - `/{business}/owned_pages` would answer, but it is outside the brief's call list (§9.7) — not run. Folded into R-915. -- The spec named `website/` for the logo; the probe uses `website/assets/logo.png` (PNG, 645×408 — Facebook photos - do not take SVG). -- No `Co-Authored-By` line on the commit: the brief forbids it (§12). +- The photo endpoint returned no `post_id` and the photo has no `is_published` — FILED: R-914 (gap the skill closes). +- The first Page miss was a Page-assignment gap (the app was assigned, the Page was not); the same key worked after + the click, no regeneration — NOT-A-FINDING: recorded in the spike doc. +- The logo: `website/assets/logo.png` (Facebook photos take no SVG) — NOT-A-FINDING. +- No `Co-Authored-By` line on the commits: the brief forbids it (§12). diff --git a/STATUS.md b/STATUS.md index 4fda85e9..cb7d1070 100644 --- a/STATUS.md +++ b/STATUS.md @@ -6,14 +6,12 @@ 0.303.0 (nothing delivered today — tonight is the second kernel night). The open-items list is at 138. Reports: `REPORT-day-2026-10-08.md` (morning), `REPORT-day2-2026-10-08.md` (afternoon), `REPORT-day3-2026-10-08.md` (evening).** -## Facebook Page (2026-10-08): the key works, but sees no Page — needs you +## Facebook Page (2026-10-08): Claude can post — the public cannot see it yet -- The robot key works. It never runs out. -- The robot has no Page. So nothing was posted, and nothing was tested on the Page. -- **Needs you (one click):** Meta Business Suite → Settings → Users → System users → felhom-cc → Assign assets → - Pages → Felhom.eu → Full control. If you do nothing: Claude cannot post. Nothing else breaks. +- The robot key works. It never runs out. After your Page click, it reaches the Felhom.eu Page. +- Test: one scheduled text post and one scheduled photo. Accents came back exact. Both deleted, and proven gone. - **Later, before real posts:** switch the Meta app to „Live". It needs a Terms of Service web address (the - legal pages item). Until then, posts are seen only by people with a role on the app. + legal pages item). If you do nothing: posts are seen only by people with a role on the app. ## Evening (2026-10-08): your ten answers (D1–D10) built — they ship tomorrow diff --git a/documentation/audits/SPIKE-facebook-page-api-2026-10-08.md b/documentation/audits/SPIKE-facebook-page-api-2026-10-08.md index 58cd50c6..246fbb71 100644 --- a/documentation/audits/SPIKE-facebook-page-api-2026-10-08.md +++ b/documentation/audits/SPIKE-facebook-page-api-2026-10-08.md @@ -1,71 +1,75 @@ # SPIKE — can Claude Code run the Felhom.eu Facebook Page? (2026-10-08) -**Verdict: the key works and never expires, but it reaches NO Page.** `/me/accounts` is empty, so the write -phases (D, E) did not run (brief §8: no Page → stop) and nothing was posted. One operator click unblocks it. +**Verdict: yes.** The system-user key is valid and never expires; it reaches the Felhom.eu Page with every task the +skill needs; a scheduled text post and a scheduled photo were created, read back byte-equal (Hungarian accents) and +deleted, each removal proven by a failed GET. **Open:** posts made while the app is in development mode are seen +only by people with a role on the app (read, not measured) — public posting needs the app switched to Live (R-915). Baseline `felhom.eu` @ `fe0dc0d03f`. Probe: `scripts/facebook/fb_probe.py` (stdlib; tests `test_fb_probe.py`). -Evidence: `facebook-page-api-2026-10-08/` (one redacted JSON per call). Graph API **v26.0** accepted (no fallback). -Run twice (`read`), same result both times. Grades: **measured** = this run; **read** = Meta's documentation, not run. +Evidence: `facebook-page-api-2026-10-08/` — `read` run at the top level, `write-test/` the passing write run, +`write-test-run1-strict-check/` the first write run (see „Removal proof"). Graph API **v26.0** accepted, no fallback. +Grades: **measured** = this run; **read** = Meta's documentation, not run. -**Architecture: no document in `documentation/architecture/` covers marketing or social media** (checked: `00`–`12`). -That is correct — the Page is a business tool, not part of the product. The decision home is `CONTEXT.md` -(entry 2026-10-08, „Facebook Page") and the rows R-914 / R-915. +**Architecture: no document in `documentation/architecture/` covers marketing or social media** (checked `00`–`12`). +Correct — the Page is a business tool, not part of the product. Decision home: `CONTEXT.md` (2026-10-08, +„Facebook Page"); rows R-914, R-915. + +**Timeline.** First `read` (twice): `/me/accounts` empty — the app was assigned to the robot, the Page was not. +The operator assigned the Page (Business settings → Pages → Felhom.eu → assign `felhom-cc`); the **same key**, +not regenerated, then saw the Page. A system-user token is not pinned to a Page list (measured). ## Findings | Question | Answer | Grade | Evidence | |---|---|---|---| -| Is the key valid? | `is_valid: true` | measured | `A1-debug-token.json` | -| Token type / app | `SYSTEM_USER`, app `2273465403490709` (`felhom.eu`) | measured | `A1` | +| Key valid? type? | `is_valid: true`, `SYSTEM_USER`, app `2273465403490709` (`felhom.eu`) | measured | `A1-debug-token.json` | | Does it expire? | `expires_at: 0`, `data_access_expires_at: 0` — never | measured | `A1` | -| Scopes | `read_insights, pages_show_list, business_management, pages_read_engagement, pages_read_user_content, pages_manage_posts, pages_manage_engagement, public_profile` | measured | `A1` | -| Granular scopes | the six `pages_*` + `business_management`, **none with `target_ids`**; `read_insights` and `public_profile` absent from the granular list | measured | `A1` | -| Who is the robot? | id `122094150717513084`, name `felhom-cc` | measured | `B1-me.json` | -| Which Page does it reach? | **none** — `/me/accounts` → `{"data": []}`, HTTP 200 | measured | `B2-me-accounts.json` | -| Page Graph ID vs browser ID `61595336666018` | not known — no Page reached | — | — | -| Page tasks / Page token | not reached | — | — | -| Read calls (Page, feed, insights) — C | not run (needs a Page token) | — | — | -| Text post + accents — D | not run (gate) | — | — | -| Photo post — E | not run (gate) | — | — | -| API version header | `facebook-api-version: v26.0` | measured | `F1-headers.json` | -| Rate header | `x-business-use-case-usage` keyed by business `4713349378884589`, type `business_integration_system_user_platform_endpoints`, all counts ≤ 1 | measured | `F1` | -| Dev-mode posts visible to the public? | **No.** „Any data generated while an app is in Development mode, such as test posts, can only be seen by role users" — and it becomes visible to everyone once the app goes Live | read | [app modes](https://developers.facebook.com/docs/development/build-and-test/app-modes) | -| Is App Review needed for our own Page? | **No** for Standard Access: it is automatic and covers users/assets with a role on the app; Advanced Access (review + business verification) is for other people's assets | read | [access levels](https://developers.facebook.com/docs/graph-api/overview/access-levels) | -| What does Live need? | display name, contact e-mail, **Terms of Service URL**, app icon, category, app purpose (each „required to switch your app to Live mode"); the page also lists a Privacy Policy URL and a data-deletion URL. The app-modes page says switch only after App Review | read | [basic settings](https://developers.facebook.com/docs/development/create-an-app/app-dashboard/basic-settings) | +| Scopes | `read_insights, pages_show_list, business_management, pages_read_engagement, pages_read_user_content, pages_manage_posts, pages_manage_engagement, public_profile`; granular scopes carry no `target_ids` | measured | `A1` | +| Robot | id `122094150717513084` (app-scoped), name `felhom-cc`; Business Suite shows it as `61595392523486` (business-scoped) — the same robot | measured | `B1-me.json` | +| Page reached | exactly one: `Felhom.eu`, **Graph ID `1360018983863273`** (the browser profile address shows `61595336666018`) | measured | `B2-me-accounts.json` | +| Page tasks | `CREATE_CONTENT, MODERATE, MESSAGING, ADVERTISE, ANALYZE, MANAGE_LEADS, VIEW_MONETIZATION_INSIGHTS` | measured | `B2` | +| Page token | derived from `/me/accounts?fields=…,access_token`; `type: PAGE`, `expires_at: 0`; a fresh value on each derivation (199 / 201 chars) | measured | `B3-debug-page-token.json` | +| Page fields | name, link, category `Information Technology Company`, about, website, `followers_count 0`, `fan_count 0` | measured | `C1-page.json` | +| Feed | 1 post (profile picture update) | measured | `C2-feed.json` | +| Insights (v26.0, `period=day`) | `page_post_engagements`, `page_follows`, `page_media_view` all answer (values 0) — none deprecated | measured | `C3-insights-*.json` | +| Scheduled text post — D | `POST /{page}/feed` `message`, `published=false`, `scheduled_publish_time=now+7d` → id `{page}_{post}`; read back `is_published: false`, `scheduled_publish_time` equal, **message hex equal** | measured | `write-test/D1`, `D2`, `D9-verdict.json` | +| Scheduled photo — E | `POST /{page}/photos` multipart `source` (`website/assets/logo.png`), `caption`, `published=false`, `scheduled_publish_time` → **only `id` (a photo id), no `post_id`**; photo `name` read back **hex equal**; DELETE on the photo id | measured | `write-test/E1`, `E3`, `E9-verdict.json` | +| Is App Review / Live needed to post? | **No refusal in development mode**: both writes answered HTTP 200 — no (#200), (#10) or (#3) | measured | `D1`, `E1` | +| Dev-mode posts visible to the public? | **No**: „Any data generated while an app is in Development mode, such as test posts, can only be seen by role users"; visible to all once the app is Live | read | [app modes](https://developers.facebook.com/docs/development/build-and-test/app-modes) | +| App Review for our own Page? | Standard Access is automatic and covers users/assets with a role on the app; Advanced Access (review + business verification) is for others' assets | read | [access levels](https://developers.facebook.com/docs/graph-api/overview/access-levels) | +| What does Live need? | display name, contact e-mail, **Terms of Service URL**, app icon, category, app purpose (each „required to switch your app to Live mode"); Privacy Policy URL and data-deletion URL listed beside them | read | [basic settings](https://developers.facebook.com/docs/development/create-an-app/app-dashboard/basic-settings) | +| Headers | `facebook-api-version: v26.0`; `x-business-use-case-usage` keyed by business `4713349378884589`, type `business_integration_system_user_platform_endpoints`; `x-app-usage` | measured | `F1-headers.json` | -## The five operator questions +## Removal proof — a deleted post answers code 10, not 100 -1. **Does the key work, does it expire?** Yes, it works. It never expires. -2. **Which Page does it reach?** None yet. The robot has no Page assigned to it. -3. **Hungarian accents and a photo?** Not tested. The test needs a Page first. -4. **Does Meta block posting until App Review or Live?** Not measured. Meta's docs say our own Page needs no App - Review. Live is a separate switch (point 5). -5. **Are development-mode posts public?** No, says Meta's documentation. Only people with a role on the app see them. - So real public posts need the app switched to Live, and Live needs a Terms of Service web address (R-813 holds - the legal pages). +| Object | DELETE | GET after DELETE (quoted) | +|---|---|---| +| text post `1360018983863273_122096071749511222` (run 1) | `{"success": true}` | (#10) „Object does not exist, cannot be loaded due to missing permission or reviewable feature, or does not support this operation…" `fbtrace_id AVitleYH5GQggv9QstbpU4Q` | +| text post `1360018983863273_122096072277511222` (run 2) | `{"success": true}` | same (#10) text, `fbtrace_id Aiogseplh0f5BKjQ8tqEzpR` | +| photo `122096072325511222` (run 2) | `{"success": true}` | (#100, subcode 33) „Unsupported get request. Object with ID '122096072325511222' does not exist…" `fbtrace_id AREMCG8p12jhITdpE8zqsPp` | -## The click that unblocks it (R-915) +Run 1 stopped (exit 7) because the probe expected code 100. Code 10 also means a missing permission, so it is +counted as removal only because the **same Page token read the same post with HTTP 200 seconds before the DELETE** +(`D2-readback.json`). `gone_error()` now accepts code 100, or code 10 with „Object does not exist" (tests in +`test_fb_probe.py`). A different-channel control — Meta Business Suite → Planner showing no scheduled post — is the +operator's look, not run here. -Meta Business Suite → **Settings → Users → System users → `felhom-cc` → Assign assets → Pages → Felhom.eu → -Full control** (at least „Content", „Community activity", „Insights"). If the Page is not in the list, first: -**Settings → Accounts → Pages → Add → add the Felhom.eu Page** to the business portfolio `4713349378884589`. -Then re-run `python3 scripts/facebook/fb_probe.py -v read` (the same key should then see the Page — granular -scopes carry no `target_ids`, so the token is not pinned to a Page list; *inferred*, re-measure). -Which of the two clicks is missing was not measured: `/{business}/owned_pages` would say, but it is outside the -brief's call list (§9.7). +## Gaps (for the skill) -## Open questions (for the re-run) +- **The photo's publish state was not read**: the photo object has no `is_published`, and no `post_id` came back, so + „scheduled, not public" is unproven for photos. Its `created_time` was the create time (16:36 UTC), while the text + post's `created_time` was its scheduled time. The skill should read scheduled photos back through the Page's + scheduled-post listing before trusting the photo path. +- Is the system user a „role user" for the dev-mode visibility rule? Not stated in the docs read; measured only after Live. -- Page Graph ID beside `61595336666018`; its `tasks`; the Page token's `type` and `expires_at`. -- Are dev-mode scheduled posts accepted at all, or refused with (#200)/(#10)? -- Is the system user a „role user" on the app for the dev-mode visibility rule? Not stated in the docs read. -- Which insights metrics are alive in v26.0 (probe asks `page_post_engagements`, `page_follows`, `page_media_view`). -- Photo endpoint: does it return `id`, `post_id` or both, and which does DELETE need. +## What the skill needs -## What the skill needs (so far) - -- Version `v26.0`; base `https://graph.facebook.com/v26.0/`. -- Token: `FACEBOOK_API` via `load_key()` (R-453 strip + asserts); sent as `Authorization: Bearer`, accepted on - `debug_token`, `/me`, `/me/accounts` (measured). -- Page token: derived at run time from `/me/accounts?fields=…,access_token`, memory only (not yet measured). +- Base `https://graph.facebook.com/v26.0/`; token `FACEBOOK_API` via `load_key()` (R-453 strip + asserts), sent as + `Authorization: Bearer`; never in a logged URL. +- Page token: `GET /me/accounts?fields=id,name,tasks,access_token`, pick `name == "Felhom.eu"` (id `1360018983863273`), + memory only, re-derive per run. +- Text: `POST /{page}/feed` form `message`, `published=false`, `scheduled_publish_time=` → `id`. +- Photo: `POST /{page}/photos` multipart `source`, `caption`, `published=false`, `scheduled_publish_time` → `id` (photo). +- Delete: `DELETE /{id}` → `{"success": true}`; prove with `GET /{id}` → error per `gone_error()`. +- Stats: `GET /{page}/insights?metric=&period=day` for the three metrics above. - Every response through `redact()`; HTTP 200 with an `error` body counts as failure. diff --git a/documentation/audits/facebook-page-api-2026-10-08/A1-debug-token.json b/documentation/audits/facebook-page-api-2026-10-08/A1-debug-token.json index 2afa6b62..65f2413a 100644 --- a/documentation/audits/facebook-page-api-2026-10-08/A1-debug-token.json +++ b/documentation/audits/facebook-page-api-2026-10-08/A1-debug-token.json @@ -1,14 +1,14 @@ { "api_version": "v26.0", - "at_utc": "2026-10-08T15:59:55Z", + "at_utc": "2026-10-08T16:35:05Z", "error": null, "files": {}, "form": {}, "headers": { "facebook-api-version": "v26.0", "x-business-use-case-usage": "{\"4713349378884589\":[{\"type\":\"business_integration_system_user_platform_endpoints\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", - "x-fb-rev": "1049703040", - "x-fb-trace-id": "FqLPoPms2rq" + "x-fb-rev": "1049711438", + "x-fb-trace-id": "FNJ9/Gkp4KM" }, "http_status": 200, "method": "GET", diff --git a/documentation/audits/facebook-page-api-2026-10-08/B1-me.json b/documentation/audits/facebook-page-api-2026-10-08/B1-me.json index aaa04b39..a845cf8b 100644 --- a/documentation/audits/facebook-page-api-2026-10-08/B1-me.json +++ b/documentation/audits/facebook-page-api-2026-10-08/B1-me.json @@ -1,14 +1,14 @@ { "api_version": "v26.0", - "at_utc": "2026-10-08T15:59:55Z", + "at_utc": "2026-10-08T16:35:06Z", "error": null, "files": {}, "form": {}, "headers": { "facebook-api-version": "v26.0", - "x-app-usage": "{\"call_count\":0,\"total_cputime\":0,\"total_time\":0}", - "x-fb-rev": "1049703040", - "x-fb-trace-id": "FsRb63t9072" + "x-app-usage": "{\"call_count\":1,\"total_cputime\":0,\"total_time\":0}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "BW55X0OgVte" }, "http_status": 200, "method": "GET", diff --git a/documentation/audits/facebook-page-api-2026-10-08/B2-me-accounts.json b/documentation/audits/facebook-page-api-2026-10-08/B2-me-accounts.json index 9c5a17ef..9a7296c5 100644 --- a/documentation/audits/facebook-page-api-2026-10-08/B2-me-accounts.json +++ b/documentation/audits/facebook-page-api-2026-10-08/B2-me-accounts.json @@ -1,14 +1,14 @@ { "api_version": "v26.0", - "at_utc": "2026-10-08T15:59:55Z", + "at_utc": "2026-10-08T16:35:06Z", "error": null, "files": {}, "form": {}, "headers": { "facebook-api-version": "v26.0", - "x-app-usage": "{\"call_count\":0,\"total_cputime\":0,\"total_time\":0}", - "x-fb-rev": "1049703040", - "x-fb-trace-id": "Boa1at49i//" + "x-app-usage": "{\"call_count\":1,\"total_cputime\":0,\"total_time\":0}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "EhWBqfrIscq" }, "http_status": 200, "method": "GET", @@ -18,7 +18,27 @@ "fields" ], "response": { - "data": [] + "data": [ + { + "id": "1360018983863273", + "name": "Felhom.eu", + "tasks": [ + "CREATE_CONTENT", + "MODERATE", + "MESSAGING", + "ADVERTISE", + "ANALYZE", + "MANAGE_LEADS", + "VIEW_MONETIZATION_INSIGHTS" + ] + } + ], + "paging": { + "cursors": { + "after": "QVFIVG1yVkVJTjcyYWRLNlN4ZAXNSY2FwQnVIa01JY2hjazlNTG94Y0oydkh3aC1hR1pvYW5hcm40elhQTTBndVQwTTV2U1VJeUtLOHVESWlXNlZA1WC1QbFlR", + "before": "QVFIVG1yVkVJTjcyYWRLNlN4ZAXNSY2FwQnVIa01JY2hjazlNTG94Y0oydkh3aC1hR1pvYW5hcm40elhQTTBndVQwTTV2U1VJeUtLOHVESWlXNlZA1WC1QbFlR" + } + } }, "step": "B2-me-accounts" } diff --git a/documentation/audits/facebook-page-api-2026-10-08/B3-debug-page-token.json b/documentation/audits/facebook-page-api-2026-10-08/B3-debug-page-token.json new file mode 100644 index 00000000..3f007244 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/B3-debug-page-token.json @@ -0,0 +1,64 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:07Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"4713349378884589\":[{\"type\":\"business_integration_system_user_platform_endpoints\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "EcvKU7hxmPy" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "debug_token", + "query_keys": [ + "input_token" + ], + "response": { + "data": { + "app_id": "2273465403490709", + "application": "felhom.eu", + "data_access_expires_at": 0, + "expires_at": 0, + "granular_scopes": [ + { + "scope": "pages_show_list" + }, + { + "scope": "business_management" + }, + { + "scope": "pages_read_engagement" + }, + { + "scope": "pages_read_user_content" + }, + { + "scope": "pages_manage_posts" + }, + { + "scope": "pages_manage_engagement" + } + ], + "is_valid": true, + "issued_at": 1791477306, + "profile_id": "1360018983863273", + "scopes": [ + "read_insights", + "pages_show_list", + "business_management", + "pages_read_engagement", + "pages_read_user_content", + "pages_manage_posts", + "pages_manage_engagement", + "public_profile" + ], + "type": "PAGE", + "user_id": "122094150717513084" + } + }, + "step": "B3-debug-page-token" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/C1-page.json b/documentation/audits/facebook-page-api-2026-10-08/C1-page.json new file mode 100644 index 00000000..8202f6e6 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/C1-page.json @@ -0,0 +1,31 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:08Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"1360018983863273\":[{\"type\":\"pages\",\"call_count\":0,\"total_cputime\":0,\"total_time\":0,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049703040", + "x-fb-trace-id": "CAO+8R7NhV1" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "1360018983863273", + "query_keys": [ + "fields" + ], + "response": { + "about": "https://felhom.eu\nSaját felhőd, saját szabályaid\nProfesszionális otthoni szerver telepítés és üzemeltetés. Te irányítasz, mi segítünk.", + "category": "Information Technology Company", + "fan_count": 0, + "followers_count": 0, + "id": "1360018983863273", + "link": "https://www.facebook.com/1360018983863273", + "name": "Felhom.eu", + "website": "https://felhom.eu/" + }, + "step": "C1-page" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/C2-feed.json b/documentation/audits/facebook-page-api-2026-10-08/C2-feed.json new file mode 100644 index 00000000..d0cb5978 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/C2-feed.json @@ -0,0 +1,36 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:09Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"1360018983863273\":[{\"type\":\"pages\",\"call_count\":0,\"total_cputime\":0,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "Cl72u8709Vx" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "1360018983863273/feed", + "query_keys": [ + "limit" + ], + "response": { + "data": [ + { + "created_time": "2026-10-08T15:31:07+0000", + "id": "1360018983863273_122096048493511222", + "story": "Felhom.eu updated their profile picture." + } + ], + "paging": { + "cursors": { + "after": "QVFIVFNyMXQyem95dnBYTXVHemxLbXp2SHBqeGo4ODlvUXc4ZATZASTjlSVm1nMlRkbklfMnZA4RFZAlVUN4RGRMcG92MmtNQ3NDMWZApRVFCTC1acEN2UFdDcHQwZAjFzNVpVTEo0MTFEc2JhekxKWlpqelZA6QTh3a2h6YjdMTElubFNfZAWxKbHBBa0t4MzJFUXlmMmlmbjlWenZA1SG5CbHhEZAkJjY3lyTk5sSVNybUZAXc293RkRYcGNmQ1l3V1BWMTJNT1NZAclBEc0tLX2xsWmRaZAE1iZAGlqeFFLdWVyb1lGUFNrbXBybzhHbnJPZAkg0ZAHktMW9hS0pjX3h4ZAFlsQTF3amFCOWpwbWhYUTBaUjU0YXdBMFhOSkg1SUd2aTBkcjh4YUx3dVFlUFNRVDF5aEt2SF8ybEFEbkw3aWp3VWtMZAEszclJrd2RaX0Q3ZAnN6aHByaWg3cWY3R25oV0FVR3JWNjVEYmhMM3FpY2NBZAXduNklweEtNdkZAwbmpPSlZADV0pEaWtubF8ySVJfUGpHMmZAtUXk0TGY1V3VtVlFJcUduQ0d6X1BULXJrc0JYbnc2dldRSW54aS0wQldaYjVwQWJXcXdNWDVzVlR2bGxpeVdEMEUyTXQ0QVBkVEVfZAVVvc1VPa180dG51allORzNKV200U0tYYWJWWGt6ODFZALUd2dkVZARko4Y0RfdnVQbjhnNXlhMFBsTzI2LXNJZA3pUeE1hbHVHdTFhemhNSldoV1d6dWRvTm4yaGJTZAzNoZA3ltRUhydC1uQ1ctbTRqdEdfUkF3TE9TZA2VrcWJBRHVQM0RWcVNCVGd1ZAVI1NmVuNnEybzV3alhtZA0tCclVtX0s0dUFnd3VaV3dZAR0l2aUxCUFl4Y3BkUUdrR2FmejIweDFJOHMyU2loem9hQXEwRjlUUzJPcWo3MG5lQWdidXdJVncxOE1kcmlncjFpM25UOFFIU0k4WXJ2QmpFQ1RfdwZDZD", + "before": "QVFIVFpHYWo5NmFwekcyenFoWXdlM1BLcElzLThTSmlrWEFRX0EyM19FaXRVVEcxT0dHSWNrejZAsQ2FxX1JZATlJ0WFVSVmFudnZAScXEwRlZA0cG90QTB3azR3d0RhMzFWN3RwOHNveDFSalZAsaUx5QS04SFVGM1VIY0Jac1pxQTdWN0dGTUdNR19UVTc5VTJ3MHQ4T2xDTmFPT0EwSkhua0JYVERCREcyYThXeEJUUlprczYwczMwalJBMkRyY0JycU1ickJORGtvaGRHZAnJ5RzZArTHFHQkRkSHIxT2RHZA3Q0d011YUd1VzU3U0xRelVxX01aeVdMTk9LSWs1ZAzJZATDJINVM2YnZAlUGVNMEFpVnlQdlRDODB1cUQxVkd5LUVQQXg2YXlMTGFDdWtuM0R6a3JIVTh1X2tnTVZAIQS16QU1sYlgxZAjdydGR4YXZASelRtRzFRNFVzOGlEYlcxV09XbGhhVnNnQlNrOFZAlTU43NnJVdU5qTEg4UWp0WFZAyQVo4bTQwOWx3UnZABMk5ndUVCTDZAQWmZAfeGJfTHZAJVm5Yclh0S0t6bGdhNERseDViMy14LW1iSlI2YnVVMDd1R0ZAuUmZAtWVdlcVc4aWthdjNrV010WUVoMUpWMmRJM202aktVY2RsZAjdPalBOQVcyTmw5MVdUZAUFYNjFNV1FRRk9QWTRTUmxnQ1RvdmNQd0U3VnVUQ3VzY3l3ZATBJTlYyVGVRZAjZAEVUxnRDZAVTktZAY1B1R0cwYVZAaN0dTX2F3TUwwWTVfcER4WTNmbUhuRFRWVmtDWTV5bTRZAbS1DbDRQQWpueDFLbVAzMEgxdWhLaTJuQWFhUl9OTDA2QkVkWWJUVXJZAbDZANRVgySm9BWWFHc1pYanVfZA1NJMGRoSXg1M3RlTmFTUThuMnhHZAER2LXlQM1VxN3V0Y25qNG1QUTBDamtMS3pVSDRUUkItY2djb3ZAQMncyTV9ia05IV2NWUQZDZD" + } + } + }, + "step": "C2-feed" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/C3-insights-page_follows.json b/documentation/audits/facebook-page-api-2026-10-08/C3-insights-page_follows.json new file mode 100644 index 00000000..464adc79 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/C3-insights-page_follows.json @@ -0,0 +1,47 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:11Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"1360018983863273\":[{\"type\":\"pages\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "AZ0G4VAh70U" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "1360018983863273/insights", + "query_keys": [ + "metric", + "period" + ], + "response": { + "data": [ + { + "description": "Lifetime: The number of followers of your Facebook Page or profile. This is calculated as the number of follows minus the number of unfollows over the lifetime of your Facebook Page or profile. ", + "id": "1360018983863273/insights/page_follows/day", + "name": "page_follows", + "period": "day", + "title": "Lifetime Total Follows", + "values": [ + { + "end_time": "2026-10-06T07:00:00+0000", + "value": 0 + }, + { + "end_time": "2026-10-07T07:00:00+0000", + "value": 0 + } + ] + } + ], + "paging": { + "next": "https://graph.facebook.com/v26.0/1360018983863273/insights?metric=page_follows&period=day&since=1791356400&until=1791529200", + "previous": "https://graph.facebook.com/v26.0/1360018983863273/insights?metric=page_follows&period=day&since=1791010800&until=1791183600" + } + }, + "step": "C3-insights-page_follows" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/C3-insights-page_media_view.json b/documentation/audits/facebook-page-api-2026-10-08/C3-insights-page_media_view.json new file mode 100644 index 00000000..614087f5 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/C3-insights-page_media_view.json @@ -0,0 +1,47 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:11Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"1360018983863273\":[{\"type\":\"pages\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "GsAsI+TaEOP" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "1360018983863273/insights", + "query_keys": [ + "metric", + "period" + ], + "response": { + "data": [ + { + "description": "The number of times any content from your Page was displayed on a person's screen, including posts, stories, ads, and other content on your Page.", + "id": "1360018983863273/insights/page_media_view/day", + "name": "page_media_view", + "period": "day", + "title": "Facebook views", + "values": [ + { + "end_time": "2026-10-06T07:00:00+0000", + "value": 0 + }, + { + "end_time": "2026-10-07T07:00:00+0000", + "value": 0 + } + ] + } + ], + "paging": { + "next": "https://graph.facebook.com/v26.0/1360018983863273/insights?metric=page_media_view&period=day&since=1791356400&until=1791529200", + "previous": "https://graph.facebook.com/v26.0/1360018983863273/insights?metric=page_media_view&period=day&since=1791010800&until=1791183600" + } + }, + "step": "C3-insights-page_media_view" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/C3-insights-page_post_engagements.json b/documentation/audits/facebook-page-api-2026-10-08/C3-insights-page_post_engagements.json new file mode 100644 index 00000000..1fbd9e91 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/C3-insights-page_post_engagements.json @@ -0,0 +1,47 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:10Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"1360018983863273\":[{\"type\":\"pages\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "GmxXIA4KxV9" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "1360018983863273/insights", + "query_keys": [ + "metric", + "period" + ], + "response": { + "data": [ + { + "description": "Daily: The number of times people have engaged with your posts through like, comments and shares and more.", + "id": "1360018983863273/insights/page_post_engagements/day", + "name": "page_post_engagements", + "period": "day", + "title": "Daily Post Engagements", + "values": [ + { + "end_time": "2026-10-06T07:00:00+0000", + "value": 0 + }, + { + "end_time": "2026-10-07T07:00:00+0000", + "value": 0 + } + ] + } + ], + "paging": { + "next": "https://graph.facebook.com/v26.0/1360018983863273/insights?metric=page_post_engagements&period=day&since=1791356400&until=1791529200", + "previous": "https://graph.facebook.com/v26.0/1360018983863273/insights?metric=page_post_engagements&period=day&since=1791010800&until=1791183600" + } + }, + "step": "C3-insights-page_post_engagements" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/F1-headers.json b/documentation/audits/facebook-page-api-2026-10-08/F1-headers.json index 125ede69..5a0c040f 100644 --- a/documentation/audits/facebook-page-api-2026-10-08/F1-headers.json +++ b/documentation/audits/facebook-page-api-2026-10-08/F1-headers.json @@ -1,7 +1,7 @@ { "facebook-api-version": "v26.0", - "x-app-usage": "{\"call_count\":0,\"total_cputime\":0,\"total_time\":0}", + "x-app-usage": "{\"call_count\":1,\"total_cputime\":0,\"total_time\":0}", "x-business-use-case-usage": "{\"4713349378884589\":[{\"type\":\"business_integration_system_user_platform_endpoints\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", - "x-fb-rev": "1049703040", - "x-fb-trace-id": "FqLPoPms2rq" + "x-fb-rev": "1049711438", + "x-fb-trace-id": "FNJ9/Gkp4KM" } diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/A1-debug-token.json b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/A1-debug-token.json new file mode 100644 index 00000000..69a68097 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/A1-debug-token.json @@ -0,0 +1,63 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:16Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"4713349378884589\":[{\"type\":\"business_integration_system_user_platform_endpoints\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "DYJvk4v2fXQ" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "debug_token", + "query_keys": [ + "input_token" + ], + "response": { + "data": { + "app_id": "2273465403490709", + "application": "felhom.eu", + "data_access_expires_at": 0, + "expires_at": 0, + "granular_scopes": [ + { + "scope": "pages_show_list" + }, + { + "scope": "business_management" + }, + { + "scope": "pages_read_engagement" + }, + { + "scope": "pages_read_user_content" + }, + { + "scope": "pages_manage_posts" + }, + { + "scope": "pages_manage_engagement" + } + ], + "is_valid": true, + "issued_at": 1791474515, + "scopes": [ + "read_insights", + "pages_show_list", + "business_management", + "pages_read_engagement", + "pages_read_user_content", + "pages_manage_posts", + "pages_manage_engagement", + "public_profile" + ], + "type": "SYSTEM_USER", + "user_id": "122094150717513084" + } + }, + "step": "A1-debug-token" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/B1-me.json b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/B1-me.json new file mode 100644 index 00000000..4c48f121 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/B1-me.json @@ -0,0 +1,25 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:16Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-app-usage": "{\"call_count\":2,\"total_cputime\":0,\"total_time\":1}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "HPgeNKjXtbQ" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "me", + "query_keys": [ + "fields" + ], + "response": { + "id": "122094150717513084", + "name": "felhom-cc" + }, + "step": "B1-me" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/B2-me-accounts.json b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/B2-me-accounts.json new file mode 100644 index 00000000..453254e8 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/B2-me-accounts.json @@ -0,0 +1,44 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:18Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-app-usage": "{\"call_count\":2,\"total_cputime\":0,\"total_time\":1}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "Bx+BZmm9QFZ" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "me/accounts", + "query_keys": [ + "fields" + ], + "response": { + "data": [ + { + "id": "1360018983863273", + "name": "Felhom.eu", + "tasks": [ + "CREATE_CONTENT", + "MODERATE", + "MESSAGING", + "ADVERTISE", + "ANALYZE", + "MANAGE_LEADS", + "VIEW_MONETIZATION_INSIGHTS" + ] + } + ], + "paging": { + "cursors": { + "after": "QVFIVG1yVkVJTjcyYWRLNlN4ZAXNSY2FwQnVIa01JY2hjazlNTG94Y0oydkh3aC1hR1pvYW5hcm40elhQTTBndVQwTTV2U1VJeUtLOHVESWlXNlZA1WC1QbFlR", + "before": "QVFIVG1yVkVJTjcyYWRLNlN4ZAXNSY2FwQnVIa01JY2hjazlNTG94Y0oydkh3aC1hR1pvYW5hcm40elhQTTBndVQwTTV2U1VJeUtLOHVESWlXNlZA1WC1QbFlR" + } + } + }, + "step": "B2-me-accounts" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/B3-debug-page-token.json b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/B3-debug-page-token.json new file mode 100644 index 00000000..93b793f8 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/B3-debug-page-token.json @@ -0,0 +1,64 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:19Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"4713349378884589\":[{\"type\":\"business_integration_system_user_platform_endpoints\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "EI6RFnKIEUO" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "debug_token", + "query_keys": [ + "input_token" + ], + "response": { + "data": { + "app_id": "2273465403490709", + "application": "felhom.eu", + "data_access_expires_at": 0, + "expires_at": 0, + "granular_scopes": [ + { + "scope": "pages_show_list" + }, + { + "scope": "business_management" + }, + { + "scope": "pages_read_engagement" + }, + { + "scope": "pages_read_user_content" + }, + { + "scope": "pages_manage_posts" + }, + { + "scope": "pages_manage_engagement" + } + ], + "is_valid": true, + "issued_at": 1791477316, + "profile_id": "1360018983863273", + "scopes": [ + "read_insights", + "pages_show_list", + "business_management", + "pages_read_engagement", + "pages_read_user_content", + "pages_manage_posts", + "pages_manage_engagement", + "public_profile" + ], + "type": "PAGE", + "user_id": "122094150717513084" + } + }, + "step": "B3-debug-page-token" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/D1-create-feed.json b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/D1-create-feed.json new file mode 100644 index 00000000..a74b55e5 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/D1-create-feed.json @@ -0,0 +1,26 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:22Z", + "error": null, + "files": {}, + "form": { + "message": "Felhom teszt – árvíztűrő tükörfúrógép. Ez a bejegyzés törlődik.", + "published": "false", + "scheduled_publish_time": "1792082119" + }, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"1360018983863273\":[{\"type\":\"pages\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "FM3vf/NFhCx" + }, + "http_status": 200, + "method": "POST", + "ok": true, + "path": "1360018983863273/feed", + "query_keys": [], + "response": { + "id": "1360018983863273_122096071749511222" + }, + "step": "D1-create-feed" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/D2-readback.json b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/D2-readback.json new file mode 100644 index 00000000..a7aa775e --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/D2-readback.json @@ -0,0 +1,28 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:22Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"1360018983863273\":[{\"type\":\"pages\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "C7dkwNPe+s/" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "1360018983863273_122096071749511222", + "query_keys": [ + "fields" + ], + "response": { + "created_time": "2026-10-15T16:35:19+0000", + "id": "1360018983863273_122096071749511222", + "is_published": false, + "message": "Felhom teszt – árvíztűrő tükörfúrógép. Ez a bejegyzés törlődik.", + "scheduled_publish_time": 1792082119 + }, + "step": "D2-readback" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/D3-delete.json b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/D3-delete.json new file mode 100644 index 00000000..cc32f9df --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/D3-delete.json @@ -0,0 +1,22 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:29Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"1360018983863273\":[{\"type\":\"pages\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "C2FfuhUasoO" + }, + "http_status": 200, + "method": "DELETE", + "ok": true, + "path": "1360018983863273_122096071749511222", + "query_keys": [], + "response": { + "success": true + }, + "step": "D3-delete" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/D4-get-after-delete.json b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/D4-get-after-delete.json new file mode 100644 index 00000000..8ba6ab5a --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/D4-get-after-delete.json @@ -0,0 +1,34 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:30Z", + "error": { + "code": 10, + "fbtrace_id": "AVitleYH5GQggv9QstbpU4Q", + "message": "(#10) Object does not exist, cannot be loaded due to missing permission or reviewable feature, or does not support this operation. This endpoint requires the 'pages_read_engagement' permission or the 'Page Public Content Access' feature. Refer to https://developers.facebook.com/docs/apps/review/login-permissions#manage-pages and https://developers.facebook.com/docs/apps/review/feature#reference-PAGES_ACCESS for details. ", + "type": "OAuthException" + }, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-app-usage": "{\"call_count\":3,\"total_cputime\":0,\"total_time\":3}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "EilWoEpK9yP" + }, + "http_status": 400, + "method": "GET", + "ok": false, + "path": "1360018983863273_122096071749511222", + "query_keys": [ + "fields" + ], + "response": { + "error": { + "code": 10, + "fbtrace_id": "AVitleYH5GQggv9QstbpU4Q", + "message": "(#10) Object does not exist, cannot be loaded due to missing permission or reviewable feature, or does not support this operation. This endpoint requires the 'pages_read_engagement' permission or the 'Page Public Content Access' feature. Refer to https://developers.facebook.com/docs/apps/review/login-permissions#manage-pages and https://developers.facebook.com/docs/apps/review/feature#reference-PAGES_ACCESS for details. ", + "type": "OAuthException" + } + }, + "step": "D4-get-after-delete" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/D9-verdict.json b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/D9-verdict.json new file mode 100644 index 00000000..cbecc278 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/D9-verdict.json @@ -0,0 +1,13 @@ +{ + "delete_ok": true, + "hex_equal": true, + "is_published": false, + "post_id": "1360018983863273_122096071749511222", + "read_hex": "46656c686f6d207465737a7420e2809320c3a17276c3ad7a74c5b172c5912074c3bc6bc3b67266c3ba72c3b367c3a9702e20457a20612062656a6567797ac3a9732074c3b6726cc59164696b2e", + "readback_ok": true, + "removed": false, + "scheduled_publish_time_read": 1792082119, + "scheduled_publish_time_sent": 1792082119, + "sent_hex": "46656c686f6d207465737a7420e2809320c3a17276c3ad7a74c5b172c5912074c3bc6bc3b67266c3ba72c3b367c3a9702e20457a20612062656a6567797ac3a9732074c3b6726cc59164696b2e", + "text_field": "message" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/F1-headers.json b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/F1-headers.json new file mode 100644 index 00000000..9244ea50 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test-run1-strict-check/F1-headers.json @@ -0,0 +1,7 @@ +{ + "facebook-api-version": "v26.0", + "x-app-usage": "{\"call_count\":2,\"total_cputime\":0,\"total_time\":1}", + "x-business-use-case-usage": "{\"4713349378884589\":[{\"type\":\"business_integration_system_user_platform_endpoints\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "DYJvk4v2fXQ" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test/A1-debug-token.json b/documentation/audits/facebook-page-api-2026-10-08/write-test/A1-debug-token.json new file mode 100644 index 00000000..f97bfd75 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test/A1-debug-token.json @@ -0,0 +1,63 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:52Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"4713349378884589\":[{\"type\":\"business_integration_system_user_platform_endpoints\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "AtHKNLek902" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "debug_token", + "query_keys": [ + "input_token" + ], + "response": { + "data": { + "app_id": "2273465403490709", + "application": "felhom.eu", + "data_access_expires_at": 0, + "expires_at": 0, + "granular_scopes": [ + { + "scope": "pages_show_list" + }, + { + "scope": "business_management" + }, + { + "scope": "pages_read_engagement" + }, + { + "scope": "pages_read_user_content" + }, + { + "scope": "pages_manage_posts" + }, + { + "scope": "pages_manage_engagement" + } + ], + "is_valid": true, + "issued_at": 1791474515, + "scopes": [ + "read_insights", + "pages_show_list", + "business_management", + "pages_read_engagement", + "pages_read_user_content", + "pages_manage_posts", + "pages_manage_engagement", + "public_profile" + ], + "type": "SYSTEM_USER", + "user_id": "122094150717513084" + } + }, + "step": "A1-debug-token" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test/B1-me.json b/documentation/audits/facebook-page-api-2026-10-08/write-test/B1-me.json new file mode 100644 index 00000000..0e2b9438 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test/B1-me.json @@ -0,0 +1,25 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:53Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-app-usage": "{\"call_count\":3,\"total_cputime\":0,\"total_time\":3}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "BvJ8ThDb6uV" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "me", + "query_keys": [ + "fields" + ], + "response": { + "id": "122094150717513084", + "name": "felhom-cc" + }, + "step": "B1-me" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test/B2-me-accounts.json b/documentation/audits/facebook-page-api-2026-10-08/write-test/B2-me-accounts.json new file mode 100644 index 00000000..b8470e6d --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test/B2-me-accounts.json @@ -0,0 +1,44 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:54Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-app-usage": "{\"call_count\":3,\"total_cputime\":0,\"total_time\":3}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "Cu/VxOlyZcD" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "me/accounts", + "query_keys": [ + "fields" + ], + "response": { + "data": [ + { + "id": "1360018983863273", + "name": "Felhom.eu", + "tasks": [ + "CREATE_CONTENT", + "MODERATE", + "MESSAGING", + "ADVERTISE", + "ANALYZE", + "MANAGE_LEADS", + "VIEW_MONETIZATION_INSIGHTS" + ] + } + ], + "paging": { + "cursors": { + "after": "QVFIVG1yVkVJTjcyYWRLNlN4ZAXNSY2FwQnVIa01JY2hjazlNTG94Y0oydkh3aC1hR1pvYW5hcm40elhQTTBndVQwTTV2U1VJeUtLOHVESWlXNlZA1WC1QbFlR", + "before": "QVFIVG1yVkVJTjcyYWRLNlN4ZAXNSY2FwQnVIa01JY2hjazlNTG94Y0oydkh3aC1hR1pvYW5hcm40elhQTTBndVQwTTV2U1VJeUtLOHVESWlXNlZA1WC1QbFlR" + } + } + }, + "step": "B2-me-accounts" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test/B3-debug-page-token.json b/documentation/audits/facebook-page-api-2026-10-08/write-test/B3-debug-page-token.json new file mode 100644 index 00000000..c97dea52 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test/B3-debug-page-token.json @@ -0,0 +1,64 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:54Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"4713349378884589\":[{\"type\":\"business_integration_system_user_platform_endpoints\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "HHbltPyCc/h" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "debug_token", + "query_keys": [ + "input_token" + ], + "response": { + "data": { + "app_id": "2273465403490709", + "application": "felhom.eu", + "data_access_expires_at": 0, + "expires_at": 0, + "granular_scopes": [ + { + "scope": "pages_show_list" + }, + { + "scope": "business_management" + }, + { + "scope": "pages_read_engagement" + }, + { + "scope": "pages_read_user_content" + }, + { + "scope": "pages_manage_posts" + }, + { + "scope": "pages_manage_engagement" + } + ], + "is_valid": true, + "issued_at": 1791477353, + "profile_id": "1360018983863273", + "scopes": [ + "read_insights", + "pages_show_list", + "business_management", + "pages_read_engagement", + "pages_read_user_content", + "pages_manage_posts", + "pages_manage_engagement", + "public_profile" + ], + "type": "PAGE", + "user_id": "122094150717513084" + } + }, + "step": "B3-debug-page-token" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test/D1-create-feed.json b/documentation/audits/facebook-page-api-2026-10-08/write-test/D1-create-feed.json new file mode 100644 index 00000000..26c30653 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test/D1-create-feed.json @@ -0,0 +1,26 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:56Z", + "error": null, + "files": {}, + "form": { + "message": "Felhom teszt – árvíztűrő tükörfúrógép. Ez a bejegyzés törlődik.", + "published": "false", + "scheduled_publish_time": "1792082154" + }, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"1360018983863273\":[{\"type\":\"pages\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "DUd8B9LXk6P" + }, + "http_status": 200, + "method": "POST", + "ok": true, + "path": "1360018983863273/feed", + "query_keys": [], + "response": { + "id": "1360018983863273_122096072277511222" + }, + "step": "D1-create-feed" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test/D2-readback.json b/documentation/audits/facebook-page-api-2026-10-08/write-test/D2-readback.json new file mode 100644 index 00000000..4e866fce --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test/D2-readback.json @@ -0,0 +1,28 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:35:56Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"1360018983863273\":[{\"type\":\"pages\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "HRdhjuEMeyV" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "1360018983863273_122096072277511222", + "query_keys": [ + "fields" + ], + "response": { + "created_time": "2026-10-15T16:35:54+0000", + "id": "1360018983863273_122096072277511222", + "is_published": false, + "message": "Felhom teszt – árvíztűrő tükörfúrógép. Ez a bejegyzés törlődik.", + "scheduled_publish_time": 1792082154 + }, + "step": "D2-readback" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test/D3-delete.json b/documentation/audits/facebook-page-api-2026-10-08/write-test/D3-delete.json new file mode 100644 index 00000000..fa0c897b --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test/D3-delete.json @@ -0,0 +1,22 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:36:01Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"1360018983863273\":[{\"type\":\"pages\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "D/A5QDkBvyn" + }, + "http_status": 200, + "method": "DELETE", + "ok": true, + "path": "1360018983863273_122096072277511222", + "query_keys": [], + "response": { + "success": true + }, + "step": "D3-delete" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test/D4-get-after-delete.json b/documentation/audits/facebook-page-api-2026-10-08/write-test/D4-get-after-delete.json new file mode 100644 index 00000000..c13075af --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test/D4-get-after-delete.json @@ -0,0 +1,34 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:36:01Z", + "error": { + "code": 10, + "fbtrace_id": "Aiogseplh0f5BKjQ8tqEzpR", + "message": "(#10) Object does not exist, cannot be loaded due to missing permission or reviewable feature, or does not support this operation. This endpoint requires the 'pages_read_engagement' permission or the 'Page Public Content Access' feature. Refer to https://developers.facebook.com/docs/apps/review/login-permissions#manage-pages and https://developers.facebook.com/docs/apps/review/feature#reference-PAGES_ACCESS for details. ", + "type": "OAuthException" + }, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-app-usage": "{\"call_count\":3,\"total_cputime\":0,\"total_time\":3}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "HGvMpcS6DNZ" + }, + "http_status": 400, + "method": "GET", + "ok": false, + "path": "1360018983863273_122096072277511222", + "query_keys": [ + "fields" + ], + "response": { + "error": { + "code": 10, + "fbtrace_id": "Aiogseplh0f5BKjQ8tqEzpR", + "message": "(#10) Object does not exist, cannot be loaded due to missing permission or reviewable feature, or does not support this operation. This endpoint requires the 'pages_read_engagement' permission or the 'Page Public Content Access' feature. Refer to https://developers.facebook.com/docs/apps/review/login-permissions#manage-pages and https://developers.facebook.com/docs/apps/review/feature#reference-PAGES_ACCESS for details. ", + "type": "OAuthException" + } + }, + "step": "D4-get-after-delete" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test/D9-verdict.json b/documentation/audits/facebook-page-api-2026-10-08/write-test/D9-verdict.json new file mode 100644 index 00000000..b6e666c1 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test/D9-verdict.json @@ -0,0 +1,13 @@ +{ + "delete_ok": true, + "hex_equal": true, + "is_published": false, + "post_id": "1360018983863273_122096072277511222", + "read_hex": "46656c686f6d207465737a7420e2809320c3a17276c3ad7a74c5b172c5912074c3bc6bc3b67266c3ba72c3b367c3a9702e20457a20612062656a6567797ac3a9732074c3b6726cc59164696b2e", + "readback_ok": true, + "removed": true, + "scheduled_publish_time_read": 1792082154, + "scheduled_publish_time_sent": 1792082154, + "sent_hex": "46656c686f6d207465737a7420e2809320c3a17276c3ad7a74c5b172c5912074c3bc6bc3b67266c3ba72c3b367c3a9702e20457a20612062656a6567797ac3a9732074c3b6726cc59164696b2e", + "text_field": "message" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test/E1-create-photo.json b/documentation/audits/facebook-page-api-2026-10-08/write-test/E1-create-photo.json new file mode 100644 index 00000000..291fd534 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test/E1-create-photo.json @@ -0,0 +1,28 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:36:02Z", + "error": null, + "files": { + "source": "website/assets/logo.png" + }, + "form": { + "caption": "Felhom teszt – árvíztűrő tükörfúrógép. Ez a bejegyzés törlődik.", + "published": "false", + "scheduled_publish_time": "1792082161" + }, + "headers": { + "facebook-api-version": "v26.0", + "x-app-usage": "{\"call_count\":3,\"total_cputime\":0,\"total_time\":3}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "GolqXC3uHmr" + }, + "http_status": 200, + "method": "POST", + "ok": true, + "path": "1360018983863273/photos", + "query_keys": [], + "response": { + "id": "122096072325511222" + }, + "step": "E1-create-photo" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test/E3-readback-photo.json b/documentation/audits/facebook-page-api-2026-10-08/write-test/E3-readback-photo.json new file mode 100644 index 00000000..991e3d89 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test/E3-readback-photo.json @@ -0,0 +1,27 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:36:03Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-business-use-case-usage": "{\"1360018983863273\":[{\"type\":\"pages\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "CHEO4EK9tRu" + }, + "http_status": 200, + "method": "GET", + "ok": true, + "path": "122096072325511222", + "query_keys": [ + "fields" + ], + "response": { + "created_time": "2026-10-08T16:36:01+0000", + "id": "122096072325511222", + "link": "https://www.facebook.com/photo.php?fbid=122096072325511222&set=p.122096072325511222&type=3", + "name": "Felhom teszt – árvíztűrő tükörfúrógép. Ez a bejegyzés törlődik." + }, + "step": "E3-readback-photo" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test/E4-delete-photo_id.json b/documentation/audits/facebook-page-api-2026-10-08/write-test/E4-delete-photo_id.json new file mode 100644 index 00000000..01476a27 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test/E4-delete-photo_id.json @@ -0,0 +1,22 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:36:05Z", + "error": null, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-app-usage": "{\"call_count\":3,\"total_cputime\":0,\"total_time\":3}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "GLyQDZQjYM7" + }, + "http_status": 200, + "method": "DELETE", + "ok": true, + "path": "122096072325511222", + "query_keys": [], + "response": { + "success": true + }, + "step": "E4-delete-photo_id" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test/E6-get-photo-after-delete.json b/documentation/audits/facebook-page-api-2026-10-08/write-test/E6-get-photo-after-delete.json new file mode 100644 index 00000000..de4bbb7f --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test/E6-get-photo-after-delete.json @@ -0,0 +1,36 @@ +{ + "api_version": "v26.0", + "at_utc": "2026-10-08T16:36:06Z", + "error": { + "code": 100, + "error_subcode": 33, + "fbtrace_id": "AREMCG8p12jhITdpE8zqsPp", + "message": "Unsupported get request. Object with ID '122096072325511222' does not exist, cannot be loaded due to missing permissions, or does not support this operation. Please read the Graph API documentation at https://developers.facebook.com/docs/graph-api", + "type": "GraphMethodException" + }, + "files": {}, + "form": {}, + "headers": { + "facebook-api-version": "v26.0", + "x-app-usage": "{\"call_count\":4,\"total_cputime\":0,\"total_time\":3}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "F4K3tUPDt03" + }, + "http_status": 400, + "method": "GET", + "ok": false, + "path": "122096072325511222", + "query_keys": [ + "fields" + ], + "response": { + "error": { + "code": 100, + "error_subcode": 33, + "fbtrace_id": "AREMCG8p12jhITdpE8zqsPp", + "message": "Unsupported get request. Object with ID '122096072325511222' does not exist, cannot be loaded due to missing permissions, or does not support this operation. Please read the Graph API documentation at https://developers.facebook.com/docs/graph-api", + "type": "GraphMethodException" + } + }, + "step": "E6-get-photo-after-delete" +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test/E9-verdict.json b/documentation/audits/facebook-page-api-2026-10-08/write-test/E9-verdict.json new file mode 100644 index 00000000..8ec64d2c --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test/E9-verdict.json @@ -0,0 +1,17 @@ +{ + "create_keys": [ + "id" + ], + "delete_first_ok": true, + "delete_first_target": "photo_id", + "logo": "website/assets/logo.png", + "photo": { + "hex_equal": true, + "name_hex": "46656c686f6d207465737a7420e2809320c3a17276c3ad7a74c5b172c5912074c3bc6bc3b67266c3ba72c3b367c3a9702e20457a20612062656a6567797ac3a9732074c3b6726cc59164696b2e", + "readback_ok": true + }, + "photo_id": "122096072325511222", + "photo_removed": true, + "post_id": null, + "post_removed": null +} diff --git a/documentation/audits/facebook-page-api-2026-10-08/write-test/F1-headers.json b/documentation/audits/facebook-page-api-2026-10-08/write-test/F1-headers.json new file mode 100644 index 00000000..3d8641b8 --- /dev/null +++ b/documentation/audits/facebook-page-api-2026-10-08/write-test/F1-headers.json @@ -0,0 +1,7 @@ +{ + "facebook-api-version": "v26.0", + "x-app-usage": "{\"call_count\":3,\"total_cputime\":0,\"total_time\":3}", + "x-business-use-case-usage": "{\"4713349378884589\":[{\"type\":\"business_integration_system_user_platform_endpoints\",\"call_count\":1,\"total_cputime\":1,\"total_time\":1,\"estimated_time_to_regain_access\":0}]}", + "x-fb-rev": "1049711438", + "x-fb-trace-id": "AtHKNLek902" +} diff --git a/documentation/backlog/OPEN-ITEMS.md b/documentation/backlog/OPEN-ITEMS.md index d3f730d7..7a5f7c8e 100644 --- a/documentation/backlog/OPEN-ITEMS.md +++ b/documentation/backlog/OPEN-ITEMS.md @@ -274,8 +274,8 @@ stopping line that lies. | **R-901** | Business & legal | P2 | **Two kinds of a household's data outlive the deletion of the customer, and no document says when they go.** FOUND 2026-10-08 (R-813 drafting), read in source: the hub keeps `events` and `notification_log` on purpose after a customer is deleted (`hub/internal/store/customer_delete.go:24-26`, „the audit trail outlives every lifecycle tier") and nothing prunes `notification_log`; DooPlex's copy of ep0 (`ep0-copy`) pulls with `remove-vanished false` and prunes only to keep-weekly 8 (`runbooks/ep0-datastore-copy.md`), so a deleted customer's last 8 weekly encrypted whole-guest copies stay on DooPlex with no end date. A privacy notice cannot promise deletion until this is decided. **-- 2026-10-08 14:16 operator ruling D9 (`09` §3 decision 193):** yes — CC installs the DooPlex job, dry run first, then daily, after the 2026-10-09 releases are read back. | **READY — ruled 2026-10-08 09:04 (`09` §3 decision 181): audit rows (`events`, `notification_log`) of a deleted customer kept 1 year, then deleted; the customer's `ep0-copy` namespace removed within 30 days; both go into the privacy-notice draft.** Close only when both are live. | R-813 | Build the hub's daily deletion (ships with the next hub release) and the DooPlex `ep0-copy` removal job (written; run needs the operator's word); write both times into the privacy-notice draft | CC | | **R-89** | Business & legal | P4 | Retention as a per-customer **commercial** policy on the hub | READY (increment 2) | — | Policy object + reconciler → ep0 prune job; keep box tokens write-only | CC | | **R-794** | Business & legal | P4 | **[P3-LOW] redis 7.4 (RSALv2 / SSPL, not OSI) runs as a private cache in seven apps: dawarich, docmost, immich, nextcloud, outline, paperless-ngx, romm.** READ 2026-10-02 (`audits/licences-2026-10-02/TABLE.md`). Read as permitted (a private cache only its app uses is not Redis offered as a service — inferred). Valkey (BSD-3) or redis 8 (AGPL option) removes the question. **Needs:** a ladder step per app to valkey or redis 8, through the harness — no hurry. | **READY — rank P3-LOW; owner: CC** **Re-ranked 2026-10-03: P3→P4: the row itself says no hurry; usage read as permitted.** | — | — | CC | -| **R-914** | Business & legal | P4 | **Write the Felhom Facebook Page skill from the spike's findings.** Spike 2026-10-08 (`audits/SPIKE-facebook-page-api-2026-10-08.md`): the system-user key is valid and never expires, but reaches no Page, so the post/photo/read paths are unmeasured. Probe `scripts/facebook/fb_probe.py`. | **BLOCKED** — on R-915 (the Page is not assigned to the robot) | R-915 | After R-915: re-run `fb_probe.py -v read`, then `write-test` (scheduled post + photo, read back, deleted); finish the spike table; then write the skill (drafts scheduled for operator review by default) | CC | -| **R-915** | Business & legal | P4 | **The Facebook robot (`felhom-cc`) has no Page, and the Meta app is in development mode.** MEASURED 2026-10-08: `/me/accounts` returns `{"data": []}` (`audits/facebook-page-api-2026-10-08/B2-me-accounts.json`). READ (Meta docs, cited in the spike): posts made in development mode are seen only by people with a role on the app; Live needs display name, contact e-mail, a Terms of Service URL, an app icon, a category and the app purpose (privacy-policy and data-deletion URLs listed beside them). | **WAITING-ON-OPERATOR** | — | (1) Meta Business Suite → Settings → Users → System users → felhom-cc → Assign assets → Pages → Felhom.eu → Full control (if the Page is not listed: Settings → Accounts → Pages → Add it first). (2) Before real posts: switch the app to Live — needs the Terms of Service URL (R-813). If nothing is done: CC cannot post; nothing breaks | operator | +| **R-914** | Business & legal | P4 | **Write the Felhom Facebook Page skill from the spike's findings.** Spike 2026-10-08 (`audits/SPIKE-facebook-page-api-2026-10-08.md`): key valid, never expires; the Page (`1360018983863273`) is reached with CREATE_CONTENT/MODERATE/ANALYZE; a scheduled text post and a scheduled photo were created, read back byte-equal and deleted (removal proven). Probe `scripts/facebook/fb_probe.py`. Gap to close in the skill: a scheduled photo's publish state was not read (no `post_id` returned). | **READY — owner: CC** | — | Write the skill (drafts scheduled for operator review by default); read a scheduled photo back through the Page's scheduled-post listing | CC | +| **R-915** | Business & legal | P4 | **The Meta app `felhom.eu` is in development mode, so posts it makes are seen only by people with a role on the app.** READ 2026-10-08 (Meta docs, cited in the spike); not measured. MEASURED: development mode does not refuse posting (both test writes HTTP 200). Live needs display name, contact e-mail, a Terms of Service URL, an app icon, a category and the app purpose (privacy-policy and data-deletion URLs listed beside them). The robot's Page assignment, missing at first, was done by the operator the same day. | **WAITING-ON-OPERATOR** | R-813 (the Terms of Service URL) | Before real public posts: switch the app to Live in the Meta developer page. If nothing is done: posts stay invisible to the public | operator | ## Process & tooling — 23 rows (P3 3, P4 20) diff --git a/scripts/CHANGELOG.md b/scripts/CHANGELOG.md index 14d07fdb..4d49c917 100644 --- a/scripts/CHANGELOG.md +++ b/scripts/CHANGELOG.md @@ -1,3 +1,10 @@ +## facebook — fb_probe: a deleted post answers (#10) „Object does not exist" (2026-10-08, fixed without a row) + +- The first write run proved a text post gone only on code 100; Meta v26.0 answers a deleted scheduled post with + code 10 „Object does not exist, cannot be loaded due to missing permission…" (photo: code 100/33). `gone_error()` + accepts code 100, or code 10 carrying „Object does not exist"; counted only after the same token read the object + before the DELETE. 4 new tests (code-10 text, code 100, a permission-only code 10 refused, no error refused). + ## facebook — the Page access probe `scripts/facebook/fb_probe.py` (2026-10-08, spike) - Stdlib probe for the Meta Graph API (v26.0): `read` (debug_token, /me, /me/accounts, Page fields, feed, insights) and diff --git a/scripts/facebook/fb_probe.py b/scripts/facebook/fb_probe.py index 4c49f44e..09c004bb 100644 --- a/scripts/facebook/fb_probe.py +++ b/scripts/facebook/fb_probe.py @@ -263,9 +263,20 @@ def hexs(s): return (s or "").encode("utf-8").hex() +def gone_error(err): + """True when a GET's error says the object does not exist. MEASURED 2026-10-08 (v26.0, Page token): a deleted + scheduled post answers code 10 „(#10) Object does not exist, cannot be loaded due to missing permission…", not + code 100. Code 10 also means a missing permission, so callers count it only after the SAME token read the object + successfully before the DELETE (the readback is the control).""" + if not isinstance(err, dict): + return False + msg = err.get("message") or "" + return err.get("code") == 100 or (err.get("code") == 10 and "Object does not exist" in msg) + + def prove_removed(g, step, obj_id, ptok): c = g.call(step, "GET", obj_id, ptok, query={"fields": "id"}) - gone = (not c.ok) and isinstance(c.err, dict) and c.err.get("code") == 100 + gone = (not c.ok) and gone_error(c.err) log(" GET after DELETE %s: HTTP %s, removed=%s, error=%s" % (obj_id, c.status, gone, json.dumps(c.err, ensure_ascii=False))) return gone diff --git a/scripts/facebook/test_fb_probe.py b/scripts/facebook/test_fb_probe.py index 589ed585..1b47464a 100644 --- a/scripts/facebook/test_fb_probe.py +++ b/scripts/facebook/test_fb_probe.py @@ -67,5 +67,19 @@ class Redact(unittest.TestCase): self.assertEqual(fb_probe.redact(fb_probe.TEST_TEXT, secrets=[]), fb_probe.TEST_TEXT) +class GoneError(unittest.TestCase): + def test_measured_code_10_does_not_exist(self): + self.assertTrue(fb_probe.gone_error({"code": 10, "message": "(#10) Object does not exist, cannot be loaded due to missing permission"})) + + def test_code_100(self): + self.assertTrue(fb_probe.gone_error({"code": 100, "message": "Unsupported get request"})) + + def test_other_code_10_is_not_removal(self): + self.assertFalse(fb_probe.gone_error({"code": 10, "message": "(#10) Application does not have permission"})) + + def test_success_body_is_not_removal(self): + self.assertFalse(fb_probe.gone_error(None)) + + if __name__ == "__main__": unittest.main()