Spike: Facebook Page reached after the operator's Page click; scheduled post + photo created, read back byte-equal, deleted
gates / gates (push) Successful in 4m35s
gates / gates (push) Successful in 4m35s
Read phase passes (Page 1360018983863273, CREATE_CONTENT/MODERATE/ANALYZE, page token PAGE expires_at 0, three insights metrics alive on v26.0). Write test: removal check accepts Meta's code-10 'Object does not exist' (fixed without a row, 4 tests); run 1 evidence kept. R-914 READY, R-915 narrowed to Live mode.
This commit is contained in:
+30
-33
@@ -4,47 +4,44 @@ Own file, not `REPORT.md`: parallel sessions share this clone (`CLAUDE.md` workf
|
||||
|
||||
## For the operator
|
||||
|
||||
- The robot key works. It never runs out.
|
||||
- The robot sees **no Page**. So the run stopped before any post. Nothing was posted. Nothing was deleted.
|
||||
- **You do one click:** Meta Business Suite → Settings → Users → System users → `felhom-cc` → Assign assets →
|
||||
Pages → Felhom.eu → Full control. If Felhom.eu is not in the list: Settings → Accounts → Pages → add it first.
|
||||
- After that, tell Claude to re-run the probe. If you do nothing: Claude cannot post. Nothing else breaks.
|
||||
- Later, before real public posts: switch the Meta app to „Live". It needs a Terms of Service web address.
|
||||
- Yes. Claude can make posts on the Felhom.eu Page.
|
||||
- The key works. It never runs out.
|
||||
- Test: one scheduled text post and one scheduled photo. The Hungarian accents came back exact. Both are deleted.
|
||||
- **Later, before real public posts:** switch the Meta app to „Live". It needs a Terms of Service web address.
|
||||
If you do nothing: only people with a role on the app see the posts.
|
||||
- Optional check: Meta Business Suite → Planner should show no scheduled post.
|
||||
|
||||
## Results
|
||||
|
||||
| Scenario | Result | Evidence |
|
||||
|---|---|---|
|
||||
| A — key valid, long-lived | PASS: `SYSTEM_USER`, app 2273465403490709, `is_valid true`, `expires_at 0`, `data_access_expires_at 0` | `A1-debug-token.json` |
|
||||
| B — reaches the Page | **FAIL: `/me/accounts` = `{"data": []}`**; robot = `felhom-cc` (122094150717513084) | `B1`, `B2` |
|
||||
| C — read calls | not run (no Page token) | — |
|
||||
| D — scheduled text post | not run (§8: no Page → stop) | — |
|
||||
| E — scheduled photo | not run | — |
|
||||
| F — headers | `facebook-api-version: v26.0`; `x-business-use-case-usage` recorded | `F1-headers.json` |
|
||||
| F — docs (read) | dev-mode posts seen only by role users; own-Page use needs no App Review (Standard Access); Live needs ToS URL, icon, category, contact e-mail, app purpose | spike doc, with URLs |
|
||||
| A — key | PASS: `SYSTEM_USER`, app 2273465403490709, valid, `expires_at 0` | `A1-debug-token.json` |
|
||||
| B — Page | first run FAIL (no Page assigned); after the operator's click PASS: Felhom.eu `1360018983863273`, `CREATE_CONTENT` + `MODERATE` + `ANALYZE`; Page token `PAGE`, `expires_at 0` | `B2`, `B3` |
|
||||
| C — reads | PASS: Page fields, feed (1 post), 3 insights metrics alive on v26.0 | `C1`–`C3` |
|
||||
| D — text post | PASS: unpublished, schedule equal, hex equal, deleted, gone | `write-test/D*` |
|
||||
| E — photo | PASS: only a photo `id` returned (no `post_id`); caption hex equal; DELETE on the photo id; gone. **Gap:** its publish state could not be read | `write-test/E*` |
|
||||
| F — mode | no refusal in development mode (measured); dev-mode posts seen only by role users (read); Live needs ToS URL etc. (read) | spike doc |
|
||||
|
||||
Read run twice; same result. Exit code 4 both times (B failed) — the brief's green gate „exit 0 on read" is not
|
||||
met, because of the missing Page, not the script.
|
||||
- **Secret scan:** with the planted `EAAfakeprobe` control: 1 hit; after removing it: 0. No `access_token` key, no
|
||||
`access_token=` URL in the evidence. Staged-diff scan: the one hit is the test file's fake token.
|
||||
- **Accent round-trip:** D yes (message hex equal). E yes (photo caption hex equal).
|
||||
- **Teardown — Facebook:** created and deleted: text `1360018983863273_122096071749511222` (run 1),
|
||||
text `1360018983863273_122096072277511222` and photo `122096072325511222` (run 2). The GET after each DELETE:
|
||||
text posts (#10) „Object does not exist, cannot be loaded due to missing permission…"; photo (#100/33)
|
||||
„Unsupported get request. Object with ID '122096072325511222' does not exist…". **Host:** nothing provisioned.
|
||||
**Hub:** nothing created.
|
||||
- **Register:** 136 → 138; opened R-914 (CC, READY), R-915 (operator, Live mode). Closed 0.
|
||||
- `unproven.py --summary`: not walked 35 of 55 (unchanged).
|
||||
|
||||
- **Secret scan:** with the planted `EAAfakeprobe` control: 1 hit. After removing it: 0. Token tail search over
|
||||
evidence, spike doc and script: 0.
|
||||
- **Accent round-trip:** not measured (D/E not run).
|
||||
- **Teardown:** Facebook — no post created, none to delete. Host — nothing provisioned. Hub — nothing created.
|
||||
- **Register:** 136 before → 138 after; opened R-914 (skill, CC, BLOCKED on R-915), R-915 (operator, the asset
|
||||
click + Live). Closed 0.
|
||||
## Fixed without a row
|
||||
|
||||
## Files
|
||||
|
||||
`scripts/facebook/fb_probe.py`, `scripts/facebook/test_fb_probe.py`, `scripts/CHANGELOG.md`,
|
||||
`documentation/audits/SPIKE-facebook-page-api-2026-10-08.md`, `documentation/audits/facebook-page-api-2026-10-08/`,
|
||||
`documentation/backlog/OPEN-ITEMS.md`, `CONTEXT.md`, `STATUS.md`, this report.
|
||||
- The probe proved removal on code 100 only; Meta answers a deleted post with code 10. Run 1 stopped (exit 7) on a
|
||||
post that was in fact gone (same token read it 200 just before). `gone_error()` + 4 tests; run 2 passed.
|
||||
|
||||
## Observations
|
||||
|
||||
- The granular scopes carry no `target_ids`, and `read_insights` is in `scopes` but not in `granular_scopes` —
|
||||
NOT-A-FINDING: recorded in the spike table; re-check after R-915.
|
||||
- Which of the two clicks is missing (asset assignment vs Page not in the portfolio) was not measured:
|
||||
`/{business}/owned_pages` would answer, but it is outside the brief's call list (§9.7) — not run. Folded into R-915.
|
||||
- The spec named `website/` for the logo; the probe uses `website/assets/logo.png` (PNG, 645×408 — Facebook photos
|
||||
do not take SVG).
|
||||
- No `Co-Authored-By` line on the commit: the brief forbids it (§12).
|
||||
- The photo endpoint returned no `post_id` and the photo has no `is_published` — FILED: R-914 (gap the skill closes).
|
||||
- The first Page miss was a Page-assignment gap (the app was assigned, the Page was not); the same key worked after
|
||||
the click, no regeneration — NOT-A-FINDING: recorded in the spike doc.
|
||||
- The logo: `website/assets/logo.png` (Facebook photos take no SVG) — NOT-A-FINDING.
|
||||
- No `Co-Authored-By` line on the commits: the brief forbids it (§12).
|
||||
|
||||
Reference in New Issue
Block a user