fix(facebook): map page-permission (code 190) errors to a curated message - #1912
Closed
giladresisi wants to merge 1 commit into
Closed
giladresisi wants to merge 1 commit into
giladresisi wants to merge 1 commit into
Conversation
…sage Facebook rejects page publishes with OAuthException code 190 and the message "...permission(s) must be granted before impersonating a user's page" when the connected user lacks the required page-level permissions. Unlike the token-validation 190 variants this is not fixed by reconnecting, so it is mapped as a non-retryable bad-body with an actionable message instead of falling through to the 'Unknown Error' placeholder. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Strix Security ReviewNo security issues found. Updated for Reviewed by Strix |
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
This was referenced Aug 18, 2026
Collaborator
Author
|
Closing: this mapping will be added to #1719 instead (that PR is being updated to handle the same error case, together with its generic code 190 handling, so the two do not conflict). Not finished yet, will land there. |
This was referenced Aug 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What kind of change does this PR introduce?
Bug fix / UX improvement
Why was this change needed?
A customer with several Facebook Pages had posts failing on some pages only, every time, with this Graph API response:
Although it carries code 190, this is a page-permission problem (the connected Facebook user lacks adequate access on that specific Page), not an expired/invalid token: sibling pages under the same account publish fine, and the customer had already reconnected without effect.
FacebookProvider.handleErrorsonly recognizes the token-validation 190 variants (Error validating access token,REVOKED_ACCESS_TOKEN), so this body fell through to theUnknown Errorplaceholder — the failure email said nothing useful and the customer could not self-serve.This adds a curated
bad-bodymapping on the distinctivebefore impersonating a user's pagephrase:bad-body(non-retryable) rather thanrefresh-token, because reconnecting alone does not fix it and flagging the channel as needing re-auth would be misleading. Placed before the existing bare'490'substring check so it takes precedence.Companion to #1892, which maps the sibling
(#200)permission error; together with #1868 (curated calendar tooltips) the user sees the actionable message directly on the failed post.Reference on this error string: https://docs.contentstudio.io/article/688-facebook-errors (same message, attributed to missing page administration access).
Other information:
Verified against production data: on the affected pages 100% of attempts carried this exact body (dozens of occurrences across three pages, continuing after a fresh reconnect), while the customer's other pages published normally.
Checklist:
🤖 Generated with Claude Code