Files
felhom.eu/REPORT-facebook-page-api.md
T
admin e9e6300cfc
gates / gates (push) Successful in 4m35s
Spike: Facebook Page reached after the operator's Page click; scheduled post + photo created, read back byte-equal, deleted
Read phase passes (Page 1360018983863273, CREATE_CONTENT/MODERATE/ANALYZE, page token PAGE expires_at 0, three insights
metrics alive on v26.0). Write test: removal check accepts Meta's code-10 'Object does not exist' (fixed without a row,
4 tests); run 1 evidence kept. R-914 READY, R-915 narrowed to Live mode.
2026-10-08 18:38:25 +02:00

48 lines
3.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# REPORT — spike: can Claude Code run the Felhom.eu Facebook Page? (2026-10-08)
Own file, not `REPORT.md`: parallel sessions share this clone (`CLAUDE.md` workflow rule).
## For the operator
- Yes. Claude can make posts on the Felhom.eu Page.
- The key works. It never runs out.
- Test: one scheduled text post and one scheduled photo. The Hungarian accents came back exact. Both are deleted.
- **Later, before real public posts:** switch the Meta app to „Live". It needs a Terms of Service web address.
If you do nothing: only people with a role on the app see the posts.
- Optional check: Meta Business Suite → Planner should show no scheduled post.
## Results
| Scenario | Result | Evidence |
|---|---|---|
| A — key | PASS: `SYSTEM_USER`, app 2273465403490709, valid, `expires_at 0` | `A1-debug-token.json` |
| B — Page | first run FAIL (no Page assigned); after the operator's click PASS: Felhom.eu `1360018983863273`, `CREATE_CONTENT` + `MODERATE` + `ANALYZE`; Page token `PAGE`, `expires_at 0` | `B2`, `B3` |
| C — reads | PASS: Page fields, feed (1 post), 3 insights metrics alive on v26.0 | `C1`–`C3` |
| D — text post | PASS: unpublished, schedule equal, hex equal, deleted, gone | `write-test/D*` |
| E — photo | PASS: only a photo `id` returned (no `post_id`); caption hex equal; DELETE on the photo id; gone. **Gap:** its publish state could not be read | `write-test/E*` |
| F — mode | no refusal in development mode (measured); dev-mode posts seen only by role users (read); Live needs ToS URL etc. (read) | spike doc |
- **Secret scan:** with the planted `EAAfakeprobe` control: 1 hit; after removing it: 0. No `access_token` key, no
`access_token=` URL in the evidence. Staged-diff scan: the one hit is the test file's fake token.
- **Accent round-trip:** D yes (message hex equal). E yes (photo caption hex equal).
- **Teardown — Facebook:** created and deleted: text `1360018983863273_122096071749511222` (run 1),
text `1360018983863273_122096072277511222` and photo `122096072325511222` (run 2). The GET after each DELETE:
text posts (#10) „Object does not exist, cannot be loaded due to missing permission…"; photo (#100/33)
„Unsupported get request. Object with ID '122096072325511222' does not exist…". **Host:** nothing provisioned.
**Hub:** nothing created.
- **Register:** 136 → 138; opened R-914 (CC, READY), R-915 (operator, Live mode). Closed 0.
- `unproven.py --summary`: not walked 35 of 55 (unchanged).
## Fixed without a row
- The probe proved removal on code 100 only; Meta answers a deleted post with code 10. Run 1 stopped (exit 7) on a
post that was in fact gone (same token read it 200 just before). `gone_error()` + 4 tests; run 2 passed.
## Observations
- The photo endpoint returned no `post_id` and the photo has no `is_published` — FILED: R-914 (gap the skill closes).
- The first Page miss was a Page-assignment gap (the app was assigned, the Page was not); the same key worked after
the click, no regeneration — NOT-A-FINDING: recorded in the spike doc.
- The logo: `website/assets/logo.png` (Facebook photos take no SVG) — NOT-A-FINDING.
- No `Co-Authored-By` line on the commits: the brief forbids it (§12).