{
  "url": "https://apps.facebook.com",
  "auditedAt": "2026-07-28T04:30:52.086Z",
  "mode": "report",
  "status": "partial",
  "statusDetail": "Public login, consent, signup and recovery surfaces were inspected. 5 authenticated/error-state checks were blocked by the absence of an authorized test account or controlled backend.",
  "page": {
    "appType": "hybrid",
    "framework": "Meta/Facebook server shell with client-rendered UI",
    "notes": "apps.facebook.com redirects to https://www.facebook.com/# for the desktop evidence and to a mobile unified login URL under Lighthouse. Authenticated app content was not accessible."
  },
  "evidenceUsed": [
    "screenshot",
    "transition-video",
    "layout-metrics",
    "dom",
    "evaluate-probe",
    "trace",
    "har",
    "headers",
    "cookies",
    "trackers",
    "secrets",
    "images",
    "discoverability",
    "heap-summary",
    "lighthouse"
  ],
  "guidanceConsulted": [
    "dark-mode",
    "accessibility",
    "forms",
    "html",
    "css",
    "performance",
    "security",
    "privacy",
    "same-document-transitions",
    "size-aware-styling",
    "passkeys",
    "language-detection",
    "webmcp",
    "agentic-forms",
    "manage-recurring-intervals"
  ],
  "artifacts": [
    {
      "type": "screenshot",
      "path": "evidence/desktop.png",
      "caption": "Desktop first load with consent modal",
      "condition": "viewport 1440x900",
      "findingIds": [
        "F02",
        "F28"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/mobile.png",
      "caption": "Narrow viewport first load",
      "condition": "viewport 360x800",
      "findingIds": [
        "F02",
        "F04",
        "F14",
        "F28"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/dark.png",
      "caption": "Dark preference capture",
      "condition": "prefers-color-scheme: dark",
      "findingIds": [
        "F01"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/high-contrast.png",
      "caption": "High contrast preference capture",
      "condition": "prefers-contrast: more",
      "findingIds": []
    },
    {
      "type": "dom",
      "path": "evidence/dom.json",
      "caption": "Rendered DOM and computed styles",
      "condition": "default",
      "findingIds": [
        "F01"
      ]
    },
    {
      "type": "other",
      "path": "evidence/probe.json",
      "caption": "Semantic, metadata, form, focus and link probe",
      "condition": "default",
      "findingIds": [
        "F03",
        "F05",
        "F13",
        "F18",
        "F23"
      ]
    },
    {
      "type": "other",
      "path": "evidence/after-consent.json",
      "caption": "State after declining optional cookies",
      "condition": "consent declined",
      "findingIds": []
    },
    {
      "type": "video",
      "path": "evidence/consent-dismiss.mp4",
      "caption": "Consent dismissal interaction",
      "condition": "desktop",
      "findingIds": []
    },
    {
      "type": "layout",
      "path": "evidence/layout-mobile.json",
      "caption": "Narrow viewport layout, CLS and long tasks",
      "condition": "viewport 360x800",
      "findingIds": [
        "F04",
        "F07",
        "F14",
        "F16"
      ]
    },
    {
      "type": "trace",
      "path": "evidence/trace.json",
      "caption": "DevTools performance trace",
      "condition": "cold load",
      "findingIds": []
    },
    {
      "type": "trace-summary",
      "path": "evidence/trace-summary.json",
      "caption": "Compact trace metrics",
      "condition": "cold load",
      "findingIds": [
        "F06",
        "F08",
        "F25"
      ]
    },
    {
      "type": "har",
      "path": "evidence/network.har",
      "caption": "HAR 1.2 network capture",
      "condition": "cold load",
      "findingIds": [
        "F09"
      ]
    },
    {
      "type": "har-summary",
      "path": "evidence/network-summary.json",
      "caption": "Compact network signals",
      "condition": "cold load",
      "findingIds": [
        "F09",
        "F10",
        "F25",
        "F26"
      ]
    },
    {
      "type": "lighthouse",
      "path": "evidence/lighthouse.json",
      "caption": "Lighthouse mobile audit; final URL is Facebook mobile login",
      "condition": "mobile",
      "findingIds": [
        "F06",
        "F10",
        "F11",
        "F12",
        "F14",
        "F15",
        "F17"
      ]
    },
    {
      "type": "other",
      "path": "evidence/headers.json",
      "caption": "Security response headers",
      "condition": "default",
      "findingIds": [
        "F20",
        "F21"
      ]
    },
    {
      "type": "other",
      "path": "evidence/cookies.json",
      "caption": "Pre-consent cookie audit",
      "condition": "default",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/trackers.json",
      "caption": "Third-party and tracker origins",
      "condition": "default",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/secrets.json",
      "caption": "Client-side secret scan",
      "condition": "default",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/images.json",
      "caption": "Image dimensions, formats, loading and alt audit",
      "condition": "default",
      "findingIds": [
        "F07",
        "F16",
        "F24"
      ]
    },
    {
      "type": "discoverability",
      "path": "evidence/discoverability.json",
      "caption": "Raw HTML/rendered content comparison",
      "condition": "JavaScript on/off",
      "findingIds": [
        "F19",
        "F22"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-rendered.png",
      "caption": "Rendered browser view",
      "condition": "JavaScript enabled",
      "findingIds": [
        "F19",
        "F22"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-crawler.png",
      "caption": "Crawler view",
      "condition": "JavaScript disabled",
      "findingIds": [
        "F19",
        "F22"
      ]
    },
    {
      "type": "heap",
      "path": "evidence/heap-baseline.json",
      "caption": "Baseline heap summary",
      "condition": "baseline",
      "findingIds": [
        "F27"
      ]
    },
    {
      "type": "heap",
      "path": "evidence/heap-post.json",
      "caption": "Heap after ten focus/blur cycles",
      "condition": "post interaction",
      "findingIds": [
        "F27"
      ]
    },
    {
      "type": "other",
      "path": "evidence/reduced-motion.json",
      "caption": "Reduced-motion animation/CSS probe",
      "condition": "prefers-reduced-motion: reduce",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/platform-probe.json",
      "caption": "Platform feature/manifest probe",
      "condition": "default",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/resource-dom-probe.json",
      "caption": "Script/style placement and modern CSS usage",
      "condition": "default",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/signup.png",
      "caption": "Signup archetype first load",
      "condition": "desktop",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/recovery.png",
      "caption": "Account recovery archetype first load",
      "condition": "desktop",
      "findingIds": []
    }
  ],
  "config": {
    "loaded": false
  },
  "coverage": {
    "catalogVersion": "modern-web-guidance@0.0.172",
    "catalogChecksum": "sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7",
    "expected": 58,
    "recorded": 58,
    "judged": 53,
    "blocked": 5,
    "notRun": 0,
    "missing": 0,
    "unknown": 0,
    "duplicates": 0,
    "complete": false
  },
  "checkOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-color-scheme",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "The dark-mode capture is visually identical to the light capture; DOM computed styles report color-scheme: normal and a white body/dialog.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/dark.png",
        "evidence/dom.json"
      ],
      "findingIds": [
        "F01"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-reduced-motion",
      "status": "pass",
      "confidence": "high",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "Reduced-motion emulation found no active animations and multiple CSS rules that set transition/animation duration to zero or animation-name:none.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/reduced-motion.json"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-contrast",
      "status": "pass",
      "confidence": "medium",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "The prefers-contrast:more screenshot preserves visible text, controls, outlines, and consent choices without clipping.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/high-contrast.png"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "view-transitions",
      "status": "pass",
      "confidence": "medium",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "CSS inspection finds view-transition rules and the consent dismissal completes without a jarring intermediate frame.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/resource-dom-probe.json"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "scroll-driven-animations",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement",
      "evidence": "The public login and consent surfaces contain no scroll-linked animation, parallax, carousel, or scrollytelling behavior to implement.",
      "reason": "The public login and consent surfaces contain no scroll-linked animation, parallax, carousel, or scrollytelling behavior to implement.",
      "pathIds": [
        "landing"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "physical-gestures",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement",
      "evidence": "No swipe, pull, drag, scroll-snap, or other gesture-driven interaction exists on the audited public surfaces.",
      "reason": "No swipe, pull, drag, scroll-snap, or other gesture-driven interaction exists on the audited public surfaces.",
      "pathIds": [
        "landing"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "scroll-state-aware-chrome",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement",
      "evidence": "The short public login surface has no sticky/affixed chrome or meaningful scroll-state transition.",
      "reason": "The short public login surface has no sticky/affixed chrome or meaningful scroll-state transition.",
      "pathIds": [
        "landing"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "anchored-positioning",
      "status": "pass",
      "confidence": "medium",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "CSS inspection finds anchor-positioning declarations; the consent overlay remains attached and within both tested viewport edges.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/resource-dom-probe.json"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "directs-attention",
      "status": "pass",
      "confidence": "high",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "The modal state uses a dimmed backdrop and clear action placement; after dismissal, the login heading and form become the dominant next step.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/consent-dismiss.mp4"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "no-intrusive-interruptions",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "Desktop and mobile screenshots show the page dimmed behind a modal that occupies most of the usable viewport before any user action.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/mobile.png"
      ],
      "findingIds": [
        "F02"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "semantic-dismissible-primitives",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "The DOM probe finds DIV role=dialog aria-modal=true and no dialog element.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/probe.json"
      ],
      "findingIds": [
        "F03"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "reduced-chrome",
      "status": "pass",
      "confidence": "high",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "After declining consent, the page text is a focused login form with recovery/signup actions and a low-priority footer rather than application chrome.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/after-consent.json"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "responsive-no-horizontal-scroll",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "The mobile layout reports hasViewportMeta:false, innerWidth 980, and visual scale 0.367; the screenshot renders the dialog and footer at tiny text sizes.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/mobile.png",
        "evidence/layout-mobile.json"
      ],
      "findingIds": [
        "F04"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "component-level-responsiveness",
      "status": "pass",
      "confidence": "medium",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "CSS inspection detects container-query rules in the delivered stylesheets.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/platform-probe.json"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "input-modality-aware",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "The focus probe programmatically focuses the email input and reads outline:none and box-shadow:none.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/probe.json"
      ],
      "findingIds": [
        "F05"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-purpose-and-primary-action",
      "status": "pass",
      "confidence": "high",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "After consent dismissal the body begins “Log in to Facebook” and exposes email, password, Log in, recovery and account-creation actions.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/after-consent.json"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "primary-flow-completion",
      "status": "blocked",
      "confidence": "high",
      "method": "Attempted production-flow review; credentials/control unavailable",
      "evidence": "Authentication credentials were not available, so end-to-end login and authenticated app task completion could not be exercised.",
      "reason": "Authentication credentials were not available, so end-to-end login and authenticated app task completion could not be exercised.",
      "pathIds": [
        "landing"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-system-state-and-recovery",
      "status": "blocked",
      "confidence": "high",
      "method": "Attempted production-flow review; credentials/control unavailable",
      "evidence": "Credential and network-error states could not be safely completed without a test account and controlled backend failure.",
      "reason": "Credential and network-error states could not be safely completed without a test account and controlled backend failure.",
      "pathIds": [
        "landing"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "good-core-web-vitals",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "The DevTools trace measured FCP/LCP at 7.22s; Lighthouse measured FCP 6.3s and LCP 7.7s with performance 0.58.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/trace-summary.json",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F06"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "visual-stability",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "The mobile layout observer measured CLS 0.085; all four consent images lack complete width/height dimensions.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/layout-mobile.json",
        "evidence/images.json"
      ],
      "findingIds": [
        "F07"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-main-thread",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "The trace reports two long tasks, longest 141ms, and 156.7ms total blocking time.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/trace-summary.json"
      ],
      "findingIds": [
        "F08"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-resource-delivery",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "HAR captured 43 requests and 2.05MB transferred, including 1.33MB script, 324KB CSS, and a 183KB font; a parser-inserted VeryHigh stylesheet is on the critical path.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/network.har"
      ],
      "findingIds": [
        "F09"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "trim-unused-and-duplicate-code",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "HAR reports 24 script requests and 1.33MB transferred; the largest script is 298KB and Lighthouse flags missing source maps for large first-party JavaScript.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F10"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "names-roles-labels",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "Lighthouse accessibility score is 0.78 and fails aria-required-attr and label audits.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F11"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "sufficient-contrast",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "Lighthouse fails the color-contrast audit on the mobile login variant.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F12"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "structure-and-focus",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "The DOM probe finds zero h1 and no main/nav/header/footer landmarks; focused email input has no outline or shadow.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/probe.json"
      ],
      "findingIds": [
        "F13"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "legible-text",
      "status": "pass",
      "confidence": "medium",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "Desktop screenshot shows readable line lengths and unclipped dialog/body text at the desktop condition.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/desktop.png"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "zoom-reflow-targets-and-media",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "Layout evidence shows no viewport meta on the rendered desktop response; Lighthouse fails meta-viewport because the mobile response limits scaling below the audit threshold.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/layout-mobile.json",
        "evidence/lighthouse.json",
        "evidence/mobile.png"
      ],
      "findingIds": [
        "F14"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "no-console-errors",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "Lighthouse fails the errors-in-console audit.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F15"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "sound-document-and-assets",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "The images primitive reports all four images missing a height attribute; the layout observer records CLS 0.085.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/images.json",
        "evidence/layout-mobile.json"
      ],
      "findingIds": [
        "F16"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "browser-platform-hygiene",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "Lighthouse reports one deprecated API warning and four BFCache failure reasons.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F17"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "title-and-description",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "DOM probe reports title “Facebook” and description:null.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/probe.json"
      ],
      "findingIds": [
        "F18"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "crawlable-and-mobile-friendly",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "Discoverability measured 1% raw/rendered word coverage, classified the response as a JS shell, and captured a blank crawler screenshot.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/discoverability.json",
        "evidence/discoverability-rendered.png",
        "evidence/discoverability-crawler.png"
      ],
      "findingIds": [
        "F19"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "canonical-and-indexing-signals",
      "status": "pass",
      "confidence": "medium",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "The fetch succeeds with HTTP 200 after one intentional redirect and DOM exposes canonical https://en-gb.facebook.com/.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "structured-and-shareable-metadata",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement",
      "evidence": "The audited endpoint is a generic login gateway, not an article, product, event, place, or rich public entity.",
      "reason": "The audited endpoint is a generic login gateway, not an article, product, event, place, or rich public entity.",
      "pathIds": [
        "landing"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "secure-transport-and-headers",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "Headers evidence shows HTTPS, HSTS, nosniff and CSP, but the style-src policy includes unsafe-inline.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/headers.json"
      ],
      "findingIds": [
        "F20"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "data-minimisation-and-third-parties",
      "status": "pass",
      "confidence": "medium",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "Tracker primitive found no known tracker domains and the pre-consent cookie audit found zero cookies; optional tracking is gated by consent.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/trackers.json"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "in-context-permissions-and-modern-auth",
      "status": "pass",
      "confidence": "medium",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "No permission prompt appeared on load, Notification permission stayed default, and the login identity field advertises username webauthn.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/platform-probe.json"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "defensive-browser-policies",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "Headers evidence reports referrer-policy missing while HSTS, X-Frame-Options and Permissions-Policy are present.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/headers.json"
      ],
      "findingIds": [
        "F21"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "progressive-enhancement",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "Discoverability captured an empty crawler view and 1% content coverage despite 1,954 rendered text characters.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/discoverability.json",
        "evidence/discoverability-crawler.png",
        "evidence/discoverability-rendered.png"
      ],
      "findingIds": [
        "F22"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "resilient-runtime-behaviour",
      "status": "pass",
      "confidence": "medium",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "The modal remains fully bounded at desktop and narrow viewport conditions and can be dismissed to a stable login state.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/consent-dismiss.mp4"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "offline-and-installable",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement",
      "evidence": "Facebook authentication and social data are intrinsically online; an offline/installable public login gateway would not provide a meaningful core task.",
      "reason": "Facebook authentication and social data are intrinsically online; an offline/installable public login gateway would not provide a meaningful core task.",
      "pathIds": [
        "landing"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "network-and-http-failure-states",
      "status": "blocked",
      "confidence": "high",
      "method": "Attempted production-flow review; credentials/control unavailable",
      "evidence": "No controlled backend or authenticated test account was available to simulate representative Facebook HTTP/network failures.",
      "reason": "No controlled backend or authenticated test account was available to simulate representative Facebook HTTP/network failures.",
      "pathIds": [
        "landing"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "lang-dir-and-logical-properties",
      "status": "pass",
      "confidence": "medium",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "DOM reports html lang=en and dir=ltr, with visible language-switching links and a stable layout in the tested locale.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "locale-aware-data",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement",
      "evidence": "No dates, numbers, currency, durations, or calendars are rendered on the audited public surfaces.",
      "reason": "No dates, numbers, currency, durations, or calendars are rendered on the audited public surfaces.",
      "pathIds": [
        "landing"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "time-zone-correctness",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement",
      "evidence": "No time or event data is presented or edited on the audited public surfaces.",
      "reason": "No time or event data is presented or edited on the audited public surfaces.",
      "pathIds": [
        "landing"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "no-dark-patterns",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "Desktop and mobile screenshots show “Allow all cookies” as the filled blue primary action while “Decline optional cookies” is visually secondary, despite both being valid choices.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/mobile.png"
      ],
      "findingIds": [
        "F28"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "humane-error-handling",
      "status": "blocked",
      "confidence": "high",
      "method": "Attempted production-flow review; credentials/control unavailable",
      "evidence": "Invalid credential submission was not performed against the production authentication endpoint without an authorized test account.",
      "reason": "Invalid credential submission was not performed against the production authentication endpoint without an authorized test account.",
      "pathIds": [
        "landing"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "trustworthy-input-assistance",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "DOM probe reports username webauthn on the identity field but an empty autocomplete value on the password field.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/probe.json"
      ],
      "findingIds": [
        "F23"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "safe-commercial-and-account-flows",
      "status": "blocked",
      "confidence": "high",
      "method": "Attempted production-flow review; credentials/control unavailable",
      "evidence": "Authenticated account-management, reauthentication, cancellation, and sensitive-action flows require an authorized test account.",
      "reason": "Authenticated account-management, reauthentication, cancellation, and sensitive-action flows require an authorized test account.",
      "pathIds": [
        "landing"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "optimised-assets",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "Images evidence reports four PNGs, all missing srcset and loading=lazy; each is below the fold.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/images.json"
      ],
      "findingIds": [
        "F24"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "no-wasteful-work",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "HAR records 43 requests and 2.05MB, including 24 scripts, before authentication; trace still records long tasks.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/trace-summary.json"
      ],
      "findingIds": [
        "F25"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "third-party-and-media-budget",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "Relative to apps.facebook.com, HAR attributes 34 requests and 2.052MB to other origins, primarily static.xx.fbcdn.net; even accounting for same-owner CDN delivery, the payload is disproportionate to a login form.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/network-summary.json"
      ],
      "findingIds": [
        "F26"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "structured-agent-capabilities",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement",
      "evidence": "The public login gateway exposes no safe unauthenticated agent task, and authenticated agent capabilities were outside accessible scope.",
      "reason": "The public login gateway exposes no safe unauthenticated agent task, and authenticated agent capabilities were outside accessible scope.",
      "pathIds": [
        "landing"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "on-device-inference",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement",
      "evidence": "The login and consent tasks do not benefit from on-device language-model or summarization inference.",
      "reason": "The login and consent tasks do not benefit from on-device language-model or summarization inference.",
      "pathIds": [
        "landing"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-leak-under-repeated-interaction",
      "status": "pass",
      "confidence": "medium",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "After ten repeated focus/blur cycles, node count fell from 859,958 to 859,615; no unbounded retained growth was observed in this bounded interaction.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/heap-post.json"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "bounded-footprint",
      "status": "issues",
      "confidence": "high",
      "method": "Direct browser evidence and mapped guidance review",
      "evidence": "Baseline heap summary contains about 860k nodes/heap entries and 43.8MB self size; post-focus-cycle snapshot remains about 44.0MB.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/heap-baseline.json",
        "evidence/heap-post.json"
      ],
      "findingIds": [
        "F27"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-detached-dom-or-unbounded-listeners",
      "status": "pass",
      "confidence": "medium",
      "method": "Direct evidence review against mapped guidance",
      "evidence": "Across baseline/post snapshots, total node count and object/array/closure populations did not grow after repeated focus cycles.",
      "pathIds": [
        "landing"
      ],
      "artifacts": [
        "evidence/heap-post.json"
      ]
    }
  ],
  "principleOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F01"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "provide-guided-navigation",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F02",
        "F03"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F04",
        "F05"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "expectation": "default",
      "status": "incomplete",
      "reason": "Authentication credentials were not available, so end-to-end login and authenticated app task completion could not be exercised. Credential and network-error states could not be safely completed without a test account and controlled backend failure."
    },
    {
      "principleId": "be-fast-and-stable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F06",
        "F07",
        "F08",
        "F09",
        "F10"
      ]
    },
    {
      "principleId": "be-inclusive",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F11",
        "F12",
        "F13",
        "F14"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F15",
        "F16",
        "F17"
      ]
    },
    {
      "principleId": "be-discoverable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F18",
        "F19"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F20",
        "F21"
      ]
    },
    {
      "principleId": "be-resilient",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F22"
      ]
    },
    {
      "principleId": "be-internationalised",
      "expectation": "contextual",
      "status": "pass"
    },
    {
      "principleId": "be-trustworthy",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F28",
        "F23"
      ]
    },
    {
      "principleId": "be-sustainable",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F24",
        "F25",
        "F26"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "expectation": "contextual",
      "status": "not-applicable",
      "reason": "The public login gateway exposes no safe unauthenticated agent task, and authenticated agent capabilities were outside accessible scope. The login and consent tasks do not benefit from on-device language-model or summarization inference."
    },
    {
      "principleId": "be-memory-efficient",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F27"
      ]
    }
  ],
  "paths": [
    {
      "id": "landing",
      "description": "apps.facebook.com redirect, public login and first-load cookie consent; primary accessible archetype",
      "url": "https://apps.facebook.com",
      "conditions": [
        "desktop 1440x900",
        "mobile 360x800",
        "dark color scheme",
        "higher contrast",
        "reduced motion",
        "JavaScript disabled"
      ],
      "result": "issues"
    },
    {
      "id": "signup",
      "description": "Public account-creation archetype; first-load consent state inspected, account creation not submitted",
      "url": "https://www.facebook.com/reg/",
      "conditions": [
        "desktop 1440x900"
      ],
      "result": "issues"
    },
    {
      "id": "recovery",
      "description": "Public account-recovery archetype; first-load consent state inspected, recovery not submitted",
      "url": "https://www.facebook.com/recover/initiate/",
      "conditions": [
        "desktop 1440x900"
      ],
      "result": "issues"
    },
    {
      "id": "authenticated-app",
      "description": "Authenticated Facebook app/feed and account-management journeys; excluded because no authorized test account was supplied",
      "url": "https://www.facebook.com/",
      "conditions": [
        "authentication required"
      ],
      "result": "skipped"
    }
  ],
  "findings": [
    {
      "id": "F01",
      "severity": "medium",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-color-scheme",
      "guidanceId": "dark-mode",
      "summary": "The public login and consent UI ignore the user’s dark color-scheme preference.",
      "evidence": "The dark-mode capture is visually identical to the light capture; DOM computed styles report color-scheme: normal and a white body/dialog.",
      "suggestedFix": "Declare color-scheme and retint surfaces, text, borders, and controls under prefers-color-scheme using semantic color tokens.",
      "effort": "small",
      "artifacts": [
        "evidence/dark.png",
        "evidence/dom.json"
      ]
    },
    {
      "id": "F02",
      "severity": "medium",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "maximize-content-reduce-noise",
      "principleCheckId": "no-intrusive-interruptions",
      "guidanceId": "light-dismiss-a-dialog",
      "summary": "A full-screen cookie consent dialog obscures the entire primary login experience on first load.",
      "evidence": "Desktop and mobile screenshots show the page dimmed behind a modal that occupies most of the usable viewport before any user action.",
      "suggestedFix": "Reduce the first-layer consent explanation, keep both choices immediately available, and reserve detail for an expandable secondary view.",
      "effort": "medium",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/mobile.png"
      ]
    },
    {
      "id": "F03",
      "severity": "low",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "maximize-content-reduce-noise",
      "principleCheckId": "semantic-dismissible-primitives",
      "guidanceId": "declarative-dialog-popover-control",
      "summary": "The consent modal is implemented as a custom div rather than the native dialog primitive.",
      "evidence": "The DOM probe finds DIV role=dialog aria-modal=true and no dialog element.",
      "suggestedFix": "Use a native dialog with showModal(), an accessible name, and platform dismissal behavior while retaining the clear consent actions.",
      "effort": "medium",
      "artifacts": [
        "evidence/probe.json"
      ]
    },
    {
      "id": "F04",
      "severity": "high",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "responsive-no-horizontal-scroll",
      "guidanceId": "fluid-scaling",
      "summary": "The desktop login document does not set a viewport meta tag, causing a 980 CSS-pixel layout to be scaled down on a 360px screen.",
      "evidence": "The mobile layout reports hasViewportMeta:false, innerWidth 980, and visual scale 0.367; the screenshot renders the dialog and footer at tiny text sizes.",
      "suggestedFix": "Add width=device-width, initial-scale=1 and rebuild the public login/consent layout with intrinsic fluid sizing at narrow viewports.",
      "effort": "medium",
      "artifacts": [
        "evidence/mobile.png",
        "evidence/layout-mobile.json"
      ]
    },
    {
      "id": "F05",
      "severity": "high",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "input-modality-aware",
      "guidanceId": "accessibility",
      "summary": "Keyboard focus is not visibly indicated on the first focusable login input.",
      "evidence": "The focus probe programmatically focuses the email input and reads outline:none and box-shadow:none.",
      "suggestedFix": "Provide a high-contrast :focus-visible ring and verify focus on all links, fields, consent controls, and custom role=button elements.",
      "effort": "small",
      "artifacts": [
        "evidence/probe.json"
      ]
    },
    {
      "id": "F06",
      "severity": "high",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "good-core-web-vitals",
      "guidanceId": "performance",
      "summary": "The public login experience paints far too late.",
      "evidence": "The DevTools trace measured FCP/LCP at 7.22s; Lighthouse measured FCP 6.3s and LCP 7.7s with performance 0.58.",
      "suggestedFix": "Prioritize the login/consent critical path, reduce server/document latency, and defer nonessential scripts, styles, and font work.",
      "effort": "large",
      "artifacts": [
        "evidence/trace-summary.json",
        "evidence/lighthouse.json"
      ]
    },
    {
      "id": "F07",
      "severity": "medium",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "visual-stability",
      "guidanceId": "performance",
      "summary": "Late layout movement and unreserved consent imagery reduce visual stability.",
      "evidence": "The mobile layout observer measured CLS 0.085; all four consent images lack complete width/height dimensions.",
      "suggestedFix": "Set intrinsic width and height (or aspect-ratio) on consent media and reserve all late content space.",
      "effort": "small",
      "artifacts": [
        "evidence/layout-mobile.json",
        "evidence/images.json"
      ]
    },
    {
      "id": "F08",
      "severity": "medium",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "efficient-main-thread",
      "guidanceId": "break-up-long-tasks",
      "summary": "Main-thread work includes blocking tasks during the delayed paint.",
      "evidence": "The trace reports two long tasks, longest 141ms, and 156.7ms total blocking time.",
      "suggestedFix": "Split startup work, schedule nonessential tasks after the critical login UI, and remove avoidable synchronous initialization.",
      "effort": "large",
      "artifacts": [
        "evidence/trace-summary.json"
      ]
    },
    {
      "id": "F09",
      "severity": "high",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "efficient-resource-delivery",
      "guidanceId": "performance",
      "summary": "A simple public login/consent surface transfers a heavy startup payload.",
      "evidence": "HAR captured 43 requests and 2.05MB transferred, including 1.33MB script, 324KB CSS, and a 183KB font; a parser-inserted VeryHigh stylesheet is on the critical path.",
      "suggestedFix": "Create a minimal unauthenticated bundle, inline only critical CSS, preload only the actual critical font/resource, and defer the rest.",
      "effort": "large",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/network.har"
      ]
    },
    {
      "id": "F10",
      "severity": "high",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "trim-unused-and-duplicate-code",
      "guidanceId": "identify-heavy-scripts",
      "summary": "The unauthenticated page ships 24 scripts and multiple large bundles before the user can log in.",
      "evidence": "HAR reports 24 script requests and 1.33MB transferred; the largest script is 298KB and Lighthouse flags missing source maps for large first-party JavaScript.",
      "suggestedFix": "Audit coverage and split the login/consent route so authenticated-product modules are not loaded before authentication.",
      "effort": "large",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/lighthouse.json"
      ]
    },
    {
      "id": "F11",
      "severity": "high",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-inclusive",
      "principleCheckId": "names-roles-labels",
      "guidanceId": "accessibility",
      "summary": "The mobile login variant contains incomplete ARIA and unlabeled form controls.",
      "evidence": "Lighthouse accessibility score is 0.78 and fails aria-required-attr and label audits.",
      "suggestedFix": "Use native controls where possible and ensure every role has required ARIA and every form control has a programmatic label.",
      "effort": "medium",
      "artifacts": [
        "evidence/lighthouse.json"
      ]
    },
    {
      "id": "F12",
      "severity": "medium",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-inclusive",
      "principleCheckId": "sufficient-contrast",
      "guidanceId": "accessibility",
      "summary": "Some foreground/background combinations fail minimum contrast.",
      "evidence": "Lighthouse fails the color-contrast audit on the mobile login variant.",
      "suggestedFix": "Adjust affected text and control colors to meet WCAG AA in default, dimmed, and consent states.",
      "effort": "small",
      "artifacts": [
        "evidence/lighthouse.json"
      ]
    },
    {
      "id": "F13",
      "severity": "high",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-inclusive",
      "principleCheckId": "structure-and-focus",
      "guidanceId": "accessibility",
      "summary": "The public page lacks semantic landmarks/headings and suppresses visible focus.",
      "evidence": "The DOM probe finds zero h1 and no main/nav/header/footer landmarks; focused email input has no outline or shadow.",
      "suggestedFix": "Add one descriptive h1, a main landmark and appropriate navigation/footer landmarks, then implement a coherent visible focus order.",
      "effort": "medium",
      "artifacts": [
        "evidence/probe.json"
      ]
    },
    {
      "id": "F14",
      "severity": "high",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-inclusive",
      "principleCheckId": "zoom-reflow-targets-and-media",
      "guidanceId": "accessibility",
      "summary": "The mobile variant constrains scaling and the desktop response omits a device-width viewport.",
      "evidence": "Layout evidence shows no viewport meta on the rendered desktop response; Lighthouse fails meta-viewport because the mobile response limits scaling below the audit threshold.",
      "suggestedFix": "Use an accessible viewport policy that permits zoom and ensure all public routes reflow at 320 CSS px and 400% zoom.",
      "effort": "medium",
      "artifacts": [
        "evidence/layout-mobile.json",
        "evidence/lighthouse.json",
        "evidence/mobile.png"
      ]
    },
    {
      "id": "F15",
      "severity": "medium",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "follow-best-practices",
      "principleCheckId": "no-console-errors",
      "guidanceId": "html",
      "summary": "The login load logs browser console errors.",
      "evidence": "Lighthouse fails the errors-in-console audit.",
      "suggestedFix": "Resolve the recorded network/runtime errors and add production monitoring that treats unauthenticated-route console errors as regressions.",
      "effort": "medium",
      "artifacts": [
        "evidence/lighthouse.json"
      ]
    },
    {
      "id": "F16",
      "severity": "medium",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "follow-best-practices",
      "principleCheckId": "sound-document-and-assets",
      "guidanceId": "html",
      "summary": "Consent images omit complete intrinsic dimensions.",
      "evidence": "The images primitive reports all four images missing a height attribute; the layout observer records CLS 0.085.",
      "suggestedFix": "Emit complete intrinsic dimensions for every image and retain the correct aspect ratio.",
      "effort": "small",
      "artifacts": [
        "evidence/images.json",
        "evidence/layout-mobile.json"
      ]
    },
    {
      "id": "F17",
      "severity": "medium",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "follow-best-practices",
      "principleCheckId": "browser-platform-hygiene",
      "guidanceId": "html",
      "summary": "The page uses deprecated behavior and is not eligible for the back/forward cache.",
      "evidence": "Lighthouse reports one deprecated API warning and four BFCache failure reasons.",
      "suggestedFix": "Remove deprecated API use and address unload/cache-control/runtime blockers so login, recovery, and signup history navigation can use BFCache.",
      "effort": "medium",
      "artifacts": [
        "evidence/lighthouse.json"
      ]
    },
    {
      "id": "F18",
      "severity": "medium",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-discoverable",
      "principleCheckId": "title-and-description",
      "guidanceId": "html",
      "summary": "The public landing page has only a generic title and no meta description.",
      "evidence": "DOM probe reports title “Facebook” and description:null.",
      "suggestedFix": "Add a route-specific title and concise description for the public login/landing experience.",
      "effort": "small",
      "artifacts": [
        "evidence/probe.json"
      ]
    },
    {
      "id": "F19",
      "severity": "high",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-discoverable",
      "principleCheckId": "crawlable-and-mobile-friendly",
      "guidanceId": "html",
      "summary": "Non-JavaScript crawlers receive almost none of the visible public content.",
      "evidence": "Discoverability measured 1% raw/rendered word coverage, classified the response as a JS shell, and captured a blank crawler screenshot.",
      "suggestedFix": "Server-render the public page purpose, heading, login/recovery links, and essential consent information as semantic HTML with real hrefs.",
      "effort": "large",
      "artifacts": [
        "evidence/discoverability.json",
        "evidence/discoverability-rendered.png",
        "evidence/discoverability-crawler.png"
      ]
    },
    {
      "id": "F20",
      "severity": "low",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-private-and-secure",
      "principleCheckId": "secure-transport-and-headers",
      "guidanceId": "security",
      "summary": "The CSP still permits unsafe inline styles.",
      "evidence": "Headers evidence shows HTTPS, HSTS, nosniff and CSP, but the style-src policy includes unsafe-inline.",
      "suggestedFix": "Migrate inline styles to nonce/hash-authorized styles and tighten style-src without weakening the existing CSP.",
      "effort": "large",
      "artifacts": [
        "evidence/headers.json"
      ]
    },
    {
      "id": "F21",
      "severity": "low",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-private-and-secure",
      "principleCheckId": "defensive-browser-policies",
      "guidanceId": "security",
      "summary": "The main response omits an explicit Referrer-Policy header.",
      "evidence": "Headers evidence reports referrer-policy missing while HSTS, X-Frame-Options and Permissions-Policy are present.",
      "suggestedFix": "Set a deliberate Referrer-Policy such as strict-origin-when-cross-origin and verify redirect and outbound-link behavior.",
      "effort": "small",
      "artifacts": [
        "evidence/headers.json"
      ]
    },
    {
      "id": "F22",
      "severity": "high",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-resilient",
      "principleCheckId": "progressive-enhancement",
      "guidanceId": "html",
      "summary": "The public page is effectively blank without JavaScript.",
      "evidence": "Discoverability captured an empty crawler view and 1% content coverage despite 1,954 rendered text characters.",
      "suggestedFix": "Server-render essential login, recovery, signup and consent content, then progressively enhance interactions.",
      "effort": "large",
      "artifacts": [
        "evidence/discoverability.json",
        "evidence/discoverability-crawler.png",
        "evidence/discoverability-rendered.png"
      ]
    },
    {
      "id": "F23",
      "severity": "medium",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-trustworthy",
      "principleCheckId": "trustworthy-input-assistance",
      "guidanceId": "forms",
      "summary": "The password field omits an autocomplete token.",
      "evidence": "DOM probe reports username webauthn on the identity field but an empty autocomplete value on the password field.",
      "suggestedFix": "Add autocomplete=current-password and preserve username webauthn; verify password-manager and passkey conditional UI behavior.",
      "effort": "small",
      "artifacts": [
        "evidence/probe.json"
      ]
    },
    {
      "id": "F24",
      "severity": "medium",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-sustainable",
      "principleCheckId": "optimised-assets",
      "guidanceId": "optimize-image-priority",
      "summary": "Consent imagery uses legacy PNG files without responsive sources or lazy loading below the fold.",
      "evidence": "Images evidence reports four PNGs, all missing srcset and loading=lazy; each is below the fold.",
      "suggestedFix": "Use appropriately compressed modern formats, responsive sources, and lazy loading for below-fold explanatory media.",
      "effort": "small",
      "artifacts": [
        "evidence/images.json"
      ]
    },
    {
      "id": "F25",
      "severity": "high",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-sustainable",
      "principleCheckId": "no-wasteful-work",
      "guidanceId": "deprioritize-background-fetches",
      "summary": "The login/consent route performs disproportionate startup work for its narrow purpose.",
      "evidence": "HAR records 43 requests and 2.05MB, including 24 scripts, before authentication; trace still records long tasks.",
      "suggestedFix": "Define a strict unauthenticated-route budget and delay product, analytics, and nonessential modules until needed or after consent/authentication.",
      "effort": "large",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/trace-summary.json"
      ]
    },
    {
      "id": "F26",
      "severity": "medium",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-sustainable",
      "principleCheckId": "third-party-and-media-budget",
      "guidanceId": "efficient-background-processing",
      "summary": "Cross-origin delivery dominates the app-origin request profile.",
      "evidence": "Relative to apps.facebook.com, HAR attributes 34 requests and 2.052MB to other origins, primarily static.xx.fbcdn.net; even accounting for same-owner CDN delivery, the payload is disproportionate to a login form.",
      "suggestedFix": "Reduce script/font payload and request count, cache aggressively, and load optional media only when its detail panel is opened.",
      "effort": "large",
      "artifacts": [
        "evidence/network-summary.json"
      ]
    },
    {
      "id": "F27",
      "severity": "medium",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-memory-efficient",
      "principleCheckId": "bounded-footprint",
      "guidanceId": "performance",
      "summary": "The initial heap footprint is high for a public login and consent surface.",
      "evidence": "Baseline heap summary contains about 860k nodes/heap entries and 43.8MB self size; post-focus-cycle snapshot remains about 44.0MB.",
      "suggestedFix": "Profile the unauthenticated bundle and remove product modules, large registries, and retained initialization state not needed for login.",
      "effort": "large",
      "artifacts": [
        "evidence/heap-baseline.json",
        "evidence/heap-post.json"
      ]
    },
    {
      "id": "F28",
      "severity": "medium",
      "confidence": "high",
      "pathId": "landing",
      "url": "https://apps.facebook.com",
      "principleId": "be-trustworthy",
      "principleCheckId": "no-dark-patterns",
      "guidanceId": "privacy",
      "summary": "The consent design gives the acceptance choice stronger visual emphasis than rejection.",
      "evidence": "Desktop and mobile screenshots show “Allow all cookies” as the filled blue primary action while “Decline optional cookies” is visually secondary, despite both being valid choices.",
      "suggestedFix": "Give accept and decline comparable prominence and keep the purpose and consequences equally clear.",
      "effort": "small",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/mobile.png"
      ]
    }
  ],
  "taskList": [
    {
      "id": "T01",
      "title": "Build a minimal server-rendered, responsive public login shell",
      "priority": 1,
      "findingIds": [
        "F04",
        "F06",
        "F09",
        "F10",
        "F14",
        "F19",
        "F22",
        "F25",
        "F26"
      ],
      "guidanceId": "performance",
      "status": "open"
    },
    {
      "id": "T02",
      "title": "Repair semantic structure, control labeling, contrast, and focus",
      "priority": 2,
      "findingIds": [
        "F05",
        "F11",
        "F12",
        "F13"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T03",
      "title": "Make consent compact, native, and choice-neutral",
      "priority": 3,
      "findingIds": [
        "F02",
        "F03",
        "F28"
      ],
      "guidanceId": "privacy",
      "status": "open"
    },
    {
      "id": "T04",
      "title": "Reserve and optimize consent imagery",
      "priority": 4,
      "findingIds": [
        "F07",
        "F16",
        "F24"
      ],
      "guidanceId": "optimize-image-priority",
      "status": "open"
    },
    {
      "id": "T05",
      "title": "Tighten public-route metadata and platform hygiene",
      "priority": 5,
      "findingIds": [
        "F15",
        "F17",
        "F18"
      ],
      "guidanceId": "html",
      "status": "open"
    },
    {
      "id": "T06",
      "title": "Add user-preference theming",
      "priority": 6,
      "findingIds": [
        "F01"
      ],
      "guidanceId": "dark-mode",
      "status": "open"
    },
    {
      "id": "T07",
      "title": "Tighten browser security policies",
      "priority": 7,
      "findingIds": [
        "F20",
        "F21"
      ],
      "guidanceId": "security",
      "status": "open"
    },
    {
      "id": "T08",
      "title": "Complete password-manager input assistance",
      "priority": 8,
      "findingIds": [
        "F23"
      ],
      "guidanceId": "forms",
      "status": "open"
    },
    {
      "id": "T09",
      "title": "Reduce unauthenticated memory footprint",
      "priority": 9,
      "findingIds": [
        "F27"
      ],
      "guidanceId": "performance",
      "status": "open"
    },
    {
      "id": "T10",
      "title": "Split long startup work",
      "priority": 10,
      "findingIds": [
        "F08"
      ],
      "guidanceId": "break-up-long-tasks",
      "status": "open"
    }
  ],
  "budget": {
    "pathCount": 4,
    "auditPasses": 1
  },
  "agent": "pi",
  "runId": "2026-07-28T04-30-52-086Z"
}
