Spike: Facebook Page reached after the operator's Page click; scheduled post + photo created, read back byte-equal, deleted
gates / gates (push) Successful in 4m35s

Read phase passes (Page 1360018983863273, CREATE_CONTENT/MODERATE/ANALYZE, page token PAGE expires_at 0, three insights
metrics alive on v26.0). Write test: removal check accepts Meta's code-10 'Object does not exist' (fixed without a row,
4 tests); run 1 evidence kept. R-914 READY, R-915 narrowed to Live mode.
This commit is contained in:
2026-10-08 18:38:25 +02:00
parent ff276ed7d9
commit e9e6300cfc
43 changed files with 1216 additions and 111 deletions
+30 -33
View File
@@ -4,47 +4,44 @@ Own file, not `REPORT.md`: parallel sessions share this clone (`CLAUDE.md` workf
## For the operator
- The robot key works. It never runs out.
- The robot sees **no Page**. So the run stopped before any post. Nothing was posted. Nothing was deleted.
- **You do one click:** Meta Business Suite → Settings → Users → System users → `felhom-cc` → Assign assets →
Pages → Felhom.eu → Full control. If Felhom.eu is not in the list: Settings → Accounts → Pages → add it first.
- After that, tell Claude to re-run the probe. If you do nothing: Claude cannot post. Nothing else breaks.
- Later, before real public posts: switch the Meta app to „Live". It needs a Terms of Service web address.
- Yes. Claude can make posts on the Felhom.eu Page.
- The key works. It never runs out.
- Test: one scheduled text post and one scheduled photo. The Hungarian accents came back exact. Both are deleted.
- **Later, before real public posts:** switch the Meta app to „Live". It needs a Terms of Service web address.
If you do nothing: only people with a role on the app see the posts.
- Optional check: Meta Business Suite → Planner should show no scheduled post.
## Results
| Scenario | Result | Evidence |
|---|---|---|
| A — key valid, long-lived | PASS: `SYSTEM_USER`, app 2273465403490709, `is_valid true`, `expires_at 0`, `data_access_expires_at 0` | `A1-debug-token.json` |
| B — reaches the Page | **FAIL: `/me/accounts` = `{"data": []}`**; robot = `felhom-cc` (122094150717513084) | `B1`, `B2` |
| C — read calls | not run (no Page token) | — |
| D — scheduled text post | not run (§8: no Page → stop) | — |
| E — scheduled photo | not run | — |
| F — headers | `facebook-api-version: v26.0`; `x-business-use-case-usage` recorded | `F1-headers.json` |
| F — docs (read) | dev-mode posts seen only by role users; own-Page use needs no App Review (Standard Access); Live needs ToS URL, icon, category, contact e-mail, app purpose | spike doc, with URLs |
| A — key | PASS: `SYSTEM_USER`, app 2273465403490709, valid, `expires_at 0` | `A1-debug-token.json` |
| B — Page | first run FAIL (no Page assigned); after the operator's click PASS: Felhom.eu `1360018983863273`, `CREATE_CONTENT` + `MODERATE` + `ANALYZE`; Page token `PAGE`, `expires_at 0` | `B2`, `B3` |
| C — reads | PASS: Page fields, feed (1 post), 3 insights metrics alive on v26.0 | `C1`–`C3` |
| D — text post | PASS: unpublished, schedule equal, hex equal, deleted, gone | `write-test/D*` |
| E — photo | PASS: only a photo `id` returned (no `post_id`); caption hex equal; DELETE on the photo id; gone. **Gap:** its publish state could not be read | `write-test/E*` |
| F — mode | no refusal in development mode (measured); dev-mode posts seen only by role users (read); Live needs ToS URL etc. (read) | spike doc |
Read run twice; same result. Exit code 4 both times (B failed) — the brief's green gate „exit 0 on read" is not
met, because of the missing Page, not the script.
- **Secret scan:** with the planted `EAAfakeprobe` control: 1 hit; after removing it: 0. No `access_token` key, no
`access_token=` URL in the evidence. Staged-diff scan: the one hit is the test file's fake token.
- **Accent round-trip:** D yes (message hex equal). E yes (photo caption hex equal).
- **Teardown — Facebook:** created and deleted: text `1360018983863273_122096071749511222` (run 1),
text `1360018983863273_122096072277511222` and photo `122096072325511222` (run 2). The GET after each DELETE:
text posts (#10) „Object does not exist, cannot be loaded due to missing permission…"; photo (#100/33)
„Unsupported get request. Object with ID '122096072325511222' does not exist…". **Host:** nothing provisioned.
**Hub:** nothing created.
- **Register:** 136 → 138; opened R-914 (CC, READY), R-915 (operator, Live mode). Closed 0.
- `unproven.py --summary`: not walked 35 of 55 (unchanged).
- **Secret scan:** with the planted `EAAfakeprobe` control: 1 hit. After removing it: 0. Token tail search over
evidence, spike doc and script: 0.
- **Accent round-trip:** not measured (D/E not run).
- **Teardown:** Facebook — no post created, none to delete. Host — nothing provisioned. Hub — nothing created.
- **Register:** 136 before → 138 after; opened R-914 (skill, CC, BLOCKED on R-915), R-915 (operator, the asset
click + Live). Closed 0.
## Fixed without a row
## Files
`scripts/facebook/fb_probe.py`, `scripts/facebook/test_fb_probe.py`, `scripts/CHANGELOG.md`,
`documentation/audits/SPIKE-facebook-page-api-2026-10-08.md`, `documentation/audits/facebook-page-api-2026-10-08/`,
`documentation/backlog/OPEN-ITEMS.md`, `CONTEXT.md`, `STATUS.md`, this report.
- The probe proved removal on code 100 only; Meta answers a deleted post with code 10. Run 1 stopped (exit 7) on a
post that was in fact gone (same token read it 200 just before). `gone_error()` + 4 tests; run 2 passed.
## Observations
- The granular scopes carry no `target_ids`, and `read_insights` is in `scopes` but not in `granular_scopes` —
NOT-A-FINDING: recorded in the spike table; re-check after R-915.
- Which of the two clicks is missing (asset assignment vs Page not in the portfolio) was not measured:
`/{business}/owned_pages` would answer, but it is outside the brief's call list (§9.7) — not run. Folded into R-915.
- The spec named `website/` for the logo; the probe uses `website/assets/logo.png` (PNG, 645×408 — Facebook photos
do not take SVG).
- No `Co-Authored-By` line on the commit: the brief forbids it (§12).
- The photo endpoint returned no `post_id` and the photo has no `is_published` — FILED: R-914 (gap the skill closes).
- The first Page miss was a Page-assignment gap (the app was assigned, the Page was not); the same key worked after
the click, no regeneration — NOT-A-FINDING: recorded in the spike doc.
- The logo: `website/assets/logo.png` (Facebook photos take no SVG) — NOT-A-FINDING.
- No `Co-Authored-By` line on the commits: the brief forbids it (§12).