Repository navigation
fix(facebook): map (#200) permission errors to a curated message - #1892
Merged
Merged
Conversation
Facebook rejects page publishes with an OAuthException code 200 when the connected account lacks pages_manage_posts / pages_read_engagement or sufficient page role. This previously fell through handleErrors to the 'Unknown Error' placeholder, so the failure email (and, once merged, the curated calendar tooltip from #1868) showed nothing actionable. Per Meta's docs, codes 200-299 are API Permission errors, so the (#200) marker always denotes a permissions problem. As a side effect, the preset retry helper no longer treats these as 'Unknown Error', avoiding a wasted second publish attempt. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
The same Graph (#200) OAuthException surfaces on the Instagram (Facebook-login) provider when the connected user lacks sufficient permissions on the Facebook Page linked to the Instagram account. Map it the same way as in the Facebook provider (non-retryable bad-body), placed before the generic '190,' rule; instagram-standalone delegates to the same handleErrors. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Strix Security ReviewNo security issues found. Updated for Reviewed by Strix |
5 of 14 tasks
github-merge-queue
Bot
removed this pull request from the merge queue due to a conflict with the base branch
Sep 15, 2026
…ission-mapping # Conflicts: # libraries/nestjs-libraries/src/integrations/social/facebook.provider.ts
5 of 14 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What kind of change does this PR introduce?
Bug fix / UX improvement
Why was this change needed?
A customer's Facebook Page posts were failing 100% of the time with a Graph API OAuthException, code 200:
(#200) ... requires both pages_read_engagement and pages_manage_posts as an admin with sufficient administrative permission. This happens when the connected Facebook account lacks posting rights on the Page (insufficient page role, orpages_manage_postsunchecked in the granular OAuth dialog) — reconnecting alone doesn't fix it, the user has to fix their page access on Facebook first.Because
FacebookProvider.handleErrorshad no mapping for it, the failure surfaced as theUnknown Errorplaceholder — the failure email told the customer nothing, and they had no way to self-serve.This adds a curated
bad-bodymapping on the(#200)marker:Per Meta's error-handling docs, codes 200–299 are "API Permission" errors, so
(#200)always denotes a permissions problem — the mapping can't mislabel an unrelated failure. The reverse isn't 1-1 (other permission errors use other codes, e.g. 10 or the rest of 200–299; see also this writeup on error 200 causes); those still fall back to the generic message, same as today.With this mapping, the failure email immediately shows the actionable message, and once #1868 (curated calendar error tooltips) merges, the calendar tooltip surfaces it too — so the user can self-serve: fix their Page access on Facebook, reconnect, repost.
Side effect: the
isPresetRejectionretry helper matches'Unknown Error', so a (#200) failure on a preset post previously triggered a pointless second publish attempt without the preset; with the curated message it no longer does.Update — Instagram too (cd1e40d): the same
(#200)body also shows up on the Instagram (Facebook-login) provider, where publishing goes through the Facebook Page linked to the Instagram account (5 occurrences in production since 2026-07-01, all previously surfaced asUnknown Error).InstagramProvider.handleErrorsnow maps it the same way (non-retryablebad-body, message adjusted to point at the linked Page), placed before the generic'190,'rule;instagram-standalonedelegates to the samehandleErrors, so it is covered as well.Other information:
Verified against production data: the failing page had 16/16 posts rejected with this exact error body, including after a fresh reconnect, confirming it's a page-access problem the user must resolve on Facebook's side.
Checklist:
🤖 Generated with Claude Code