{
  "url": "https://m.facebook.com",
  "auditedAt": "2026-07-26T22:05:00.000Z",
  "mode": "report",
  "status": "completed",
  "statusDetail": "Complete atomic audit of anonymous public entry, consent, login, registration, and policy templates. Authenticated product surfaces were explicitly out of representative anonymous scope.",
  "page": {
    "appType": "hybrid",
    "framework": "Meta proprietary server/client application",
    "notes": "m.facebook.com redirected differently across Chrome runs to www.facebook.com and a unified mobile login route. Findings identify route-specific evidence where relevant."
  },
  "evidenceUsed": [
    "screenshot",
    "dom",
    "layout-metrics",
    "evaluate-probe",
    "trace",
    "har",
    "discoverability/no-js",
    "security-headers",
    "cookies",
    "trackers",
    "images",
    "secrets",
    "lighthouse",
    "heap-summary",
    "curl robots/sitemap",
    "Modern Web Guidance 0.0.172"
  ],
  "guidanceConsulted": [
    "dark-mode",
    "component-specific-light-dark-theme",
    "accessibility",
    "adapt-scrollbar-to-contrast-preferences",
    "same-document-transitions",
    "cross-document-transitions",
    "group-element-transitions",
    "faster-spa-view-transitions",
    "scrollytelling",
    "parallax-scroll-effects",
    "scroll-entry-exit-effects",
    "carousel-slide-effects",
    "physics-based-easing",
    "individual-transform-properties",
    "animate-element-entry-exit",
    "animate-to-from-top-layer",
    "animate-to-intrinsic-sizes",
    "dynamic-sibling-animations",
    "interactive-content-reveal",
    "pull-to-reveal",
    "swipe-to-remove",
    "shrinking-header-on-scroll",
    "scroll-progress-indicator",
    "scroll-position-aware-elements",
    "scroll-snap-realtime-feedback",
    "scroll-snap-state-sync",
    "scroll-target-on-load",
    "soft-edge-content-fade",
    "scrollability-affordance-hints",
    "anchor-positioning-tab-underline",
    "position-aware-tooltips",
    "interest-triggered-tooltips",
    "interest-triggered-action-previews",
    "directional-navigation-transitions",
    "carousel-snap-highlights",
    "navigation-drawer",
    "stack-drill-down",
    "persistent-app-tours",
    "persistent-toast-notifications",
    "light-dismiss-a-dialog",
    "platform-controls-dismiss-dialog",
    "declarative-dialog-popover-control",
    "animated-select-picker",
    "branded-select-styling",
    "brand-consistent-forms",
    "custom-select-picker-layouts",
    "rich-media-picker",
    "complex-shapes",
    "shaped-cutouts",
    "overflow-clipping-control",
    "visually-texture-content",
    "apply-webgl-shaders",
    "interactive-content-in-3d-scenes",
    "highlight-text-ranges",
    "prevent-text-wrapping",
    "customize-scrollbar-color-and-thickness",
    "export-html-media-from-canvas",
    "fluid-scaling",
    "calculate-with-intrinsic-sizes",
    "css-layout",
    "size-aware-styling",
    "content-based-styling",
    "child-state-based-styling",
    "design-token-reactivity",
    "dynamic-sibling-styling",
    "form-fields-automatically-fit-contents",
    "improve-text-layout-and-legibility",
    "forms",
    "accessible-error-announcement",
    "required-field-feedback",
    "validate-input-after-interaction",
    "identify-inp-causes",
    "schedule-tasks-by-priority",
    "optimize-preload-priority",
    "improve-next-page-load-performance",
    "interactions-in-complex-layouts",
    "performance",
    "visually-stable-font-fallbacks",
    "break-up-long-tasks",
    "identify-heavy-scripts",
    "optimize-script-priority",
    "defer-rendering-heavy-content",
    "defer-work-until-scroll-ends",
    "optimize-image-priority",
    "conditional-async-dependencies",
    "expose-canvas-content-to-browser-features",
    "move-dom-element-without-losing-state",
    "precise-text-alignment",
    "visually-stable-mixed-fonts",
    "css",
    "html",
    "reduce-style-repetition",
    "security",
    "privacy",
    "batch-analytics-events",
    "full-session-analytics",
    "calculate-total-foreground-time",
    "passkeys",
    "passkey-registration",
    "passkey-authentication",
    "passkey-reauthentication",
    "passkey-conditional-create",
    "passkey-management",
    "flicker-free-client-side-ab-testing",
    "consistent-cross-document-transitions",
    "stabilize-reactive-state",
    "resilient-context-menus-and-nested-dropdowns",
    "persistent-top-layer-ui",
    "detect-initial-visibility-state",
    "sequence-distributed-events",
    "translator",
    "language-detection",
    "support-global-calendar-systems",
    "capture-location-agnostic-data",
    "format-human-readable-durations",
    "manage-recurring-intervals",
    "calculate-event-differentials",
    "coordinate-global-events",
    "model-partial-time-concepts",
    "search-hidden-content",
    "select-menu-interaction",
    "style-parent-with-has",
    "autofill-address-form",
    "autofill-payment-form",
    "autofill-sign-in-form",
    "autofill-sign-up-form",
    "autofill-highlight-inputs",
    "deliver-optimized-decorative-images",
    "resolution-optimized-pseudo-elements",
    "deprioritize-background-fetches",
    "efficient-background-processing",
    "webmcp",
    "agentic-forms",
    "agentic-javascript-tools",
    "language-model",
    "summarizer"
  ],
  "artifacts": [
    {
      "type": "other",
      "path": "evidence/cookies.json",
      "caption": "cookies",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/crawl-signals.txt",
      "caption": "crawl signals",
      "findingIds": [
        "F24"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/desktop.png",
      "caption": "desktop",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-crawler.png",
      "caption": "discoverability crawler",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-rendered.png",
      "caption": "discoverability rendered",
      "findingIds": []
    },
    {
      "type": "discoverability",
      "path": "evidence/discoverability.json",
      "caption": "discoverability",
      "findingIds": []
    },
    {
      "type": "dom",
      "path": "evidence/dom-mobile.json",
      "caption": "dom mobile",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/focus-targets.json",
      "caption": "focus targets",
      "findingIds": [
        "F07"
      ]
    },
    {
      "type": "other",
      "path": "evidence/headers.json",
      "caption": "headers",
      "findingIds": [
        "F26",
        "F28"
      ]
    },
    {
      "type": "heap",
      "path": "evidence/heap-baseline.json",
      "caption": "heap baseline",
      "findingIds": [
        "F36"
      ]
    },
    {
      "type": "heap",
      "path": "evidence/heap-post.json",
      "caption": "heap post",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/images.json",
      "caption": "images",
      "findingIds": [
        "F20",
        "F33"
      ]
    },
    {
      "type": "layout",
      "path": "evidence/layout-mobile.json",
      "caption": "layout mobile",
      "findingIds": [
        "F05",
        "F11",
        "F23"
      ]
    },
    {
      "type": "lighthouse",
      "path": "evidence/lighthouse-findings.json",
      "caption": "lighthouse findings",
      "findingIds": [
        "F02",
        "F14",
        "F15",
        "F18",
        "F19",
        "F21"
      ]
    },
    {
      "type": "lighthouse",
      "path": "evidence/lighthouse.json",
      "caption": "lighthouse",
      "findingIds": [
        "F13"
      ]
    },
    {
      "type": "other",
      "path": "evidence/login-validation.json",
      "caption": "login validation",
      "findingIds": [
        "F08",
        "F09",
        "F29",
        "F30"
      ]
    },
    {
      "type": "other",
      "path": "evidence/metadata-scripts.json",
      "caption": "metadata scripts",
      "findingIds": [
        "F25"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/mobile-dark.png",
      "caption": "mobile dark",
      "findingIds": [
        "F01"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/mobile-forced-colors.png",
      "caption": "mobile forced colors",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/mobile-login.png",
      "caption": "mobile login",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/mobile.png",
      "caption": "mobile",
      "findingIds": [
        "F03",
        "F17"
      ]
    },
    {
      "type": "har-summary",
      "path": "evidence/network-summary.json",
      "caption": "network summary",
      "findingIds": [
        "F12",
        "F27",
        "F34",
        "F35"
      ]
    },
    {
      "type": "har",
      "path": "evidence/network.har",
      "caption": "network",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/platform-probe.json",
      "caption": "platform probe",
      "findingIds": [
        "F06"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/privacy-mobile.png",
      "caption": "privacy mobile",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/privacy-policy.json",
      "caption": "privacy policy",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/recon-after-consent.json",
      "caption": "recon after consent",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/reduced-motion.json",
      "caption": "reduced motion",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/registration-controls.json",
      "caption": "registration controls",
      "findingIds": [
        "F31",
        "F32"
      ]
    },
    {
      "type": "other",
      "path": "evidence/registration.json",
      "caption": "registration",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/secrets.json",
      "caption": "secrets",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/structure.json",
      "caption": "structure",
      "findingIds": [
        "F04",
        "F16",
        "F22"
      ]
    },
    {
      "type": "trace-summary",
      "path": "evidence/trace-summary.json",
      "caption": "trace summary",
      "findingIds": [
        "F10"
      ]
    },
    {
      "type": "trace",
      "path": "evidence/trace.json",
      "caption": "trace",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/trackers.json",
      "caption": "trackers",
      "findingIds": []
    }
  ],
  "config": {
    "loaded": false
  },
  "coverage": {
    "catalogVersion": "modern-web-guidance@0.0.172",
    "catalogChecksum": "sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7",
    "expected": 58,
    "recorded": 58,
    "judged": 58,
    "blocked": 0,
    "notRun": 0,
    "missing": 0,
    "unknown": 0,
    "duplicates": 0,
    "complete": true
  },
  "checkOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-color-scheme",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The light and dark captures are byte-identical (51,708 bytes), and the DOM reports color-scheme: normal with a white body surface despite prefers-color-scheme: dark.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/mobile-dark.png"
      ],
      "findingIds": [
        "F01"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-reduced-motion",
      "status": "pass",
      "confidence": "medium",
      "method": "evaluate under prefers-reduced-motion: reduce",
      "evidence": "The media query matched, 33 reduced-motion CSS rules were present, and document.getAnimations() returned no running animations.",
      "artifacts": [
        "evidence/reduced-motion.json"
      ],
      "pathIds": [
        "entry-consent"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-contrast",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "Lighthouse measured the white “Allow all cookies” label on #1877f2 at 4.23:1, below the required 4.5:1 for 15px bold text.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/lighthouse-findings.json"
      ],
      "findingIds": [
        "F02"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "view-transitions",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative anonymous paths",
      "evidence": "The unauthenticated landing, consent, and policy surfaces expose no same-document route transition to animate; protected SPA navigation requires an account.",
      "reason": "The unauthenticated landing, consent, and policy surfaces expose no same-document route transition to animate; protected SPA navigation requires an account."
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "scroll-driven-animations",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative anonymous paths",
      "evidence": "The representative anonymous surfaces contain no scroll-linked animation or scrollytelling use case; native scrolling is appropriate.",
      "reason": "The representative anonymous surfaces contain no scroll-linked animation or scrollytelling use case; native scrolling is appropriate."
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "physical-gestures",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/CSS and layout inspection",
      "evidence": "The audited anonymous surfaces use native document scrolling with no observed custom gesture layer or main-thread pointer-driven interaction.",
      "artifacts": [
        "evidence/dom-mobile.json"
      ],
      "pathIds": [
        "entry-consent"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "scroll-state-aware-chrome",
      "status": "pass",
      "confidence": "medium",
      "method": "visual review of long-form policy",
      "evidence": "The Privacy Policy uses a compact persistent header and clear section hierarchy while the document itself scrolls natively.",
      "artifacts": [
        "evidence/privacy-mobile.png"
      ],
      "pathIds": [
        "privacy-policy"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "anchored-positioning",
      "status": "pass",
      "confidence": "medium",
      "method": "desktop/mobile overlay screenshots",
      "evidence": "The consent overlay remains centered and within the viewport at both desktop and mobile sizes without edge drift.",
      "artifacts": [
        "evidence/desktop.png"
      ],
      "pathIds": [
        "entry-consent"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "directs-attention",
      "status": "pass",
      "confidence": "medium",
      "method": "screenshot and task walkthrough",
      "evidence": "Login, registration, and privacy surfaces expose a clear primary heading/action; the consent dialog clearly presents the immediate choice.",
      "artifacts": [
        "evidence/desktop.png"
      ],
      "pathIds": [
        "entry-consent"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "no-intrusive-interruptions",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "Mobile and desktop screenshots show an aria-modal consent layer before any interaction, dimming and blocking the login page; on mobile it consumes most of the visible page.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/mobile.png"
      ],
      "findingIds": [
        "F03"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "semantic-dismissible-primitives",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The structure probe finds DIV role=dialog aria-modal=true, not <dialog>; focusable elements behind it appear before dialog controls in DOM focus order.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/structure.json"
      ],
      "findingIds": [
        "F04"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "reduced-chrome",
      "status": "pass",
      "confidence": "medium",
      "method": "visual review of content template",
      "evidence": "The Privacy Policy template uses a restrained header and gives most of the viewport to readable policy content.",
      "artifacts": [
        "evidence/privacy-mobile.png"
      ],
      "pathIds": [
        "privacy-policy"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "responsive-no-horizontal-scroll",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "At a requested 390px viewport, layout reports a 980px CSS viewport scaled to 0.398 and hasViewportMeta=false, making consent copy and footer links extremely small.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/layout-mobile.json"
      ],
      "findingIds": [
        "F05"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "component-level-responsiveness",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The platform probe found zero @container rules and the 390px capture renders a 980px layout scaled down rather than adapting component geometry.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/platform-probe.json"
      ],
      "findingIds": [
        "F06"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "input-modality-aware",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The focus probe successfully focused inputs, Log in, recovery, signup, and footer links, but computed outline was none and box-shadow was none for all sampled controls.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/focus-targets.json"
      ],
      "findingIds": [
        "F07"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-purpose-and-primary-action",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM text and screenshots",
      "evidence": "The entry says “Log in to Facebook”, exposes Log in and Create new account, and the registration route explains account creation.",
      "artifacts": [
        "evidence/recon-after-consent.json"
      ],
      "pathIds": [
        "login-flow"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "primary-flow-completion",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "After declining optional cookies and invoking Log in with both fields empty, the page remained unchanged with no invalid controls and no alert or live-region message.",
      "pathIds": [
        "login-flow"
      ],
      "artifacts": [
        "evidence/login-validation.json"
      ],
      "findingIds": [
        "F08"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-system-state-and-recovery",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The exercised empty-submit state produced invalid: [] and alerts: [], so users receive no state change, diagnosis, or recovery instruction.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/login-validation.json"
      ],
      "findingIds": [
        "F09"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "good-core-web-vitals",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "Lighthouse measured FCP 5.3s, LCP 7.8s, Speed Index 8.1s and performance 0.59; the raw-CDP trace independently measured FCP 4.04s and LCP 4.19s.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/trace-summary.json"
      ],
      "findingIds": [
        "F10"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "visual-stability",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The layout observer recorded CLS 0.0857 at about 2.26s; all four consent images lack a height attribute and the images probe flags missing dimensions.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/layout-mobile.json"
      ],
      "findingIds": [
        "F11"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-main-thread",
      "status": "pass",
      "confidence": "medium",
      "method": "trace and Lighthouse",
      "evidence": "The raw trace recorded 184ms TBT and Lighthouse recorded 25ms TBT, both below the common 200ms poor threshold despite two long tasks.",
      "artifacts": [
        "evidence/trace-summary.json"
      ],
      "pathIds": [
        "entry-consent"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-resource-delivery",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The HAR records 41 requests and 2,050,669 transferred bytes, including 1.33MB of JavaScript, 324KB CSS, a 183KB font, and a parser-inserted 289KB stylesheet.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/network-summary.json"
      ],
      "findingIds": [
        "F12"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "trim-unused-and-duplicate-code",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "Lighthouse’s unused-javascript audit failed with three resources while the HAR shows 24 scripts transferring 1.33MB for a simple login/consent surface.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F13"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "names-roles-labels",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "Lighthouse found a role=heading image without aria-level and an unlabeled consent checkbox; the registration probe also shows custom DIV role=button controls.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/lighthouse-findings.json"
      ],
      "findingIds": [
        "F14"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "sufficient-contrast",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "Lighthouse identifies the “Allow all cookies” text at 4.23:1 against its blue background, below 4.5:1.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/lighthouse-findings.json"
      ],
      "findingIds": [
        "F15"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "structure-and-focus",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The entry structure contains no h1, uses a DIV role=main, and the focus probe finds no visible outline or shadow on sampled controls; Lighthouse also reports malformed ARIA.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/structure.json"
      ],
      "findingIds": [
        "F16"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "legible-text",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The 390px capture uses a 980px CSS viewport at 0.398 scale; the DOM reports 12px body text, rendering key consent and footer copy at roughly 4.8 CSS pixels visually.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/mobile.png"
      ],
      "findingIds": [
        "F17"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "zoom-reflow-targets-and-media",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The CDP entry route has no viewport meta; Lighthouse’s redirected mobile login has user-scalable=no, initial-scale=1, maximum-scale=1.",
      "pathIds": [
        "login-flow"
      ],
      "artifacts": [
        "evidence/lighthouse-findings.json"
      ],
      "findingIds": [
        "F18"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "no-console-errors",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "Lighthouse captured TypeError: Cannot read properties of undefined (reading getElementsByTagName) in a first-party fbcdn script.",
      "pathIds": [
        "login-flow"
      ],
      "artifacts": [
        "evidence/lighthouse-findings.json"
      ],
      "findingIds": [
        "F19"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "sound-document-and-assets",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The images probe reports all four PNGs missing height; the DOM has a valid doctype/UTF-8 but no viewport or description, and CLS reached 0.0857.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/images.json"
      ],
      "findingIds": [
        "F20"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "browser-platform-hygiene",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "Lighthouse reports a deprecated unload listener and four back/forward-cache failure reasons on the mobile login route.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/lighthouse-findings.json"
      ],
      "findingIds": [
        "F21"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "title-and-description",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The DOM probe finds title “Facebook” but description=null; the raw HTML comparison also reports no meta description.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/structure.json"
      ],
      "findingIds": [
        "F22"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "crawlable-and-mobile-friendly",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "Links are crawlable, but the DOM and layout probes show no viewport meta and a 980px layout scaled into 390px.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/layout-mobile.json"
      ],
      "findingIds": [
        "F23"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "canonical-and-indexing-signals",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The entry canonical points to en-gb.facebook.com, robots.txt is available, but /sitemap.xml returns HTTP 500.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/crawl-signals.txt"
      ],
      "findingIds": [
        "F24"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "structured-and-shareable-metadata",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The metadata probe found no JSON-LD, microdata, hreflang, Open Graph, or description metadata on the rendered entry route.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/metadata-scripts.json"
      ],
      "findingIds": [
        "F25"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "secure-transport-and-headers",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "HTTPS, HSTS, nosniff, X-Frame-Options and Permissions-Policy are present, but Referrer-Policy is absent and style-src allows unsafe-inline.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/headers.json"
      ],
      "findingIds": [
        "F26"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "data-minimisation-and-third-parties",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "Before consent, the tracker/HAR evidence records an Instagram XHR plus 2.05MB classified cross-origin from Facebook/CDN origins; no known third-party tracker or cookie was found.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/network-summary.json"
      ],
      "findingIds": [
        "F27"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "in-context-permissions-and-modern-auth",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/security probe",
      "evidence": "No permission prompt appeared on load, no cookies were set before consent, and the username field advertises the webauthn autocomplete token.",
      "artifacts": [
        "evidence/recon-after-consent.json"
      ],
      "pathIds": [
        "login-flow"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "defensive-browser-policies",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "Headers show HSTS, DENY framing, nosniff and a broad Permissions-Policy, but no Referrer-Policy and CSP style-src unsafe-inline.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/headers.json"
      ],
      "findingIds": [
        "F28"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "progressive-enhancement",
      "status": "pass",
      "confidence": "medium",
      "method": "discoverability no-JS comparison",
      "evidence": "Raw HTML returned 200, the page was not a JS shell, and 73% of rendered content words were available without JavaScript.",
      "artifacts": [
        "evidence/discoverability.json"
      ],
      "pathIds": [
        "entry-consent"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "resilient-runtime-behaviour",
      "status": "pass",
      "confidence": "medium",
      "method": "forced-colors screenshot and responsive overlay review",
      "evidence": "The first-run dialog remained operable and visible under forced colors and at both tested viewport sizes.",
      "artifacts": [
        "evidence/mobile-forced-colors.png"
      ],
      "pathIds": [
        "entry-consent"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "offline-and-installable",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative anonymous paths",
      "evidence": "Anonymous Facebook login and policy pages are network services rather than an installable/offline task in the audited scope; no manifest or service worker was present.",
      "reason": "Anonymous Facebook login and policy pages are network services rather than an installable/offline task in the audited scope; no manifest or service worker was present."
    },
    {
      "principleId": "be-resilient",
      "checkId": "network-and-http-failure-states",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The empty login submission generated neither native invalid state nor an ARIA alert, leaving the user with no diagnosis or retry guidance.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/login-validation.json"
      ],
      "findingIds": [
        "F29"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "lang-dir-and-logical-properties",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM and route inspection",
      "evidence": "The main rendered entry has lang=en and dir=ltr, and the UI exposes multiple language choices; the policy is localized English content.",
      "artifacts": [
        "evidence/structure.json"
      ],
      "pathIds": [
        "entry-consent"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "locale-aware-data",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative anonymous paths",
      "evidence": "The sampled anonymous surfaces contain no locale-sensitive numeric/currency output to evaluate; visible dates are prose in the selected English locale.",
      "reason": "The sampled anonymous surfaces contain no locale-sensitive numeric/currency output to evaluate; visible dates are prose in the selected English locale."
    },
    {
      "principleId": "be-internationalised",
      "checkId": "time-zone-correctness",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative anonymous paths",
      "evidence": "No event scheduling or time-zone-sensitive date/time computation appears in the anonymous representative paths.",
      "reason": "No event scheduling or time-zone-sensitive date/time computation appears in the anonymous representative paths."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "no-dark-patterns",
      "status": "pass",
      "confidence": "medium",
      "method": "consent screenshots and interaction",
      "evidence": "Decline optional cookies is present alongside Allow all cookies without confirmshaming, and declining reveals the login page without retaliation.",
      "artifacts": [
        "evidence/desktop.png"
      ],
      "pathIds": [
        "entry-consent"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "humane-error-handling",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "After empty submission, no :invalid/aria-invalid controls and no alert/live region appeared.",
      "pathIds": [
        "login-flow"
      ],
      "artifacts": [
        "evidence/login-validation.json"
      ],
      "findingIds": [
        "F30"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "trustworthy-input-assistance",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "Login email uses autocomplete=\"username webauthn\", but password autocomplete is empty; all sampled registration inputs use autocomplete=\"off\".",
      "pathIds": [
        "registration"
      ],
      "artifacts": [
        "evidence/registration-controls.json"
      ],
      "findingIds": [
        "F31"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "safe-commercial-and-account-flows",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "Registration exposes DIV role=button submission and inputs without required constraints; sampled controls use autocomplete=off.",
      "pathIds": [
        "registration"
      ],
      "artifacts": [
        "evidence/registration-controls.json"
      ],
      "findingIds": [
        "F32"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "optimised-assets",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "Four below-fold PNGs have no srcset, no lazy loading, no intrinsic height, and no modern format; images transfer 118KB.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/images.json"
      ],
      "findingIds": [
        "F33"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "no-wasteful-work",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The route transfers 2.05MB and 24 scripts; the trace records two long tasks and 184ms TBT, while Lighthouse flags unused JavaScript.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/network-summary.json"
      ],
      "findingIds": [
        "F34"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "third-party-and-media-budget",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "HAR classifies 2,050,231 bytes across 32 requests as cross-origin from the m.facebook.com start URL, primarily fbcdn and www.facebook.com.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/network-summary.json"
      ],
      "findingIds": [
        "F35"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "structured-agent-capabilities",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative anonymous paths",
      "evidence": "Facebook explicitly disallows major AI-agent crawlers in robots.txt, so exposing agent-executable site capabilities conflicts with the declared indexing policy for this scope.",
      "reason": "Facebook explicitly disallows major AI-agent crawlers in robots.txt, so exposing agent-executable site capabilities conflicts with the declared indexing policy for this scope."
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "on-device-inference",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative anonymous paths",
      "evidence": "No user-facing summarisation/translation/generation task was exposed on the anonymous login, registration, consent, or policy paths that requires on-device inference.",
      "reason": "No user-facing summarisation/translation/generation task was exposed on the anonymous login, registration, consent, or policy paths that requires on-device inference."
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-leak-under-repeated-interaction",
      "status": "pass",
      "confidence": "low",
      "method": "baseline/post heap summaries after repeated consent detail interaction",
      "evidence": "After ten repeated attempts, heap self size changed from 43.9MB to 45.7MB and nodes from 860,566 to 878,221; this one-window comparison did not establish unbounded retained growth.",
      "artifacts": [
        "evidence/heap-post.json"
      ],
      "pathIds": [
        "entry-consent"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "bounded-footprint",
      "status": "issues",
      "confidence": "high",
      "method": "Active/visual/objective evidence described in linked finding",
      "evidence": "The baseline heap summary contains 860,566 nodes and 43.9MB self size before meaningful interaction, disproportionate to a login and consent surface.",
      "pathIds": [
        "entry-consent"
      ],
      "artifacts": [
        "evidence/heap-baseline.json"
      ],
      "findingIds": [
        "F36"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-detached-dom-or-unbounded-listeners",
      "status": "pass",
      "confidence": "low",
      "method": "heap constructor summary comparison",
      "evidence": "Detached* constructors did not appear among the top retained constructors in either summary; no accumulating detached-DOM signal was observed.",
      "artifacts": [
        "evidence/heap-post.json"
      ],
      "pathIds": [
        "entry-consent"
      ]
    }
  ],
  "principleOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F01",
        "F02"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "provide-guided-navigation",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F03",
        "F04"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F05",
        "F06",
        "F07"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F08",
        "F09"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F10",
        "F11",
        "F12",
        "F13"
      ]
    },
    {
      "principleId": "be-inclusive",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F14",
        "F15",
        "F16",
        "F17",
        "F18"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F19",
        "F20",
        "F21"
      ]
    },
    {
      "principleId": "be-discoverable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F22",
        "F23",
        "F24",
        "F25"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F26",
        "F27",
        "F28"
      ]
    },
    {
      "principleId": "be-resilient",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F29"
      ]
    },
    {
      "principleId": "be-internationalised",
      "expectation": "contextual",
      "status": "pass"
    },
    {
      "principleId": "be-trustworthy",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F30",
        "F31",
        "F32"
      ]
    },
    {
      "principleId": "be-sustainable",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F33",
        "F34",
        "F35"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "expectation": "contextual",
      "status": "not-applicable",
      "reason": "Facebook explicitly disallows major AI-agent crawlers in robots.txt, so exposing agent-executable site capabilities conflicts with the declared indexing policy for this scope. No user-facing summarisation/translation/generation task was exposed on the anonymous login, registration, consent, or policy paths that requires on-device inference."
    },
    {
      "principleId": "be-memory-efficient",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F36"
      ]
    }
  ],
  "paths": [
    {
      "id": "entry-consent",
      "description": "Anonymous entry and cookie-consent dialog, representing the first-run landing experience.",
      "url": "https://m.facebook.com",
      "conditions": [
        "390x844",
        "1440x900",
        "prefers-color-scheme: dark",
        "forced-colors: active",
        "prefers-reduced-motion: reduce"
      ],
      "result": "issues"
    },
    {
      "id": "login-flow",
      "description": "Cookie decline followed by the anonymous login form and empty submission, representing the primary authentication journey.",
      "url": "https://www.facebook.com/?_rdr",
      "conditions": [
        "390x844",
        "keyboard focus",
        "empty form submission"
      ],
      "result": "issues"
    },
    {
      "id": "registration",
      "description": "Public account-registration surface after cookie decline, representing the account-creation form archetype.",
      "url": "https://www.facebook.com/reg/",
      "conditions": [
        "390x844"
      ],
      "result": "issues"
    },
    {
      "id": "privacy-policy",
      "description": "Long-form public Privacy Policy, representing the content/article template.",
      "url": "https://www.facebook.com/privacy/policy/",
      "conditions": [
        "390x844"
      ],
      "result": "pass"
    },
    {
      "id": "protected-content",
      "description": "Authenticated feed, profiles, messaging, settings, and account-management surfaces were not covered because they require a real Facebook account and user data.",
      "url": "https://www.facebook.com/",
      "conditions": [
        "authentication required"
      ],
      "result": "skipped"
    }
  ],
  "findings": [
    {
      "id": "F01",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-color-scheme",
      "guidanceId": "dark-mode",
      "guidanceCategory": "user-experience",
      "severity": "medium",
      "confidence": "high",
      "summary": "The first-run experience does not follow the requested dark theme",
      "evidence": "The light and dark captures are byte-identical (51,708 bytes), and the DOM reports color-scheme: normal with a white body surface despite prefers-color-scheme: dark.",
      "artifacts": [
        "evidence/mobile-dark.png"
      ],
      "suggestedFix": "Declare color-scheme and map every first-run surface, including consent, to light/dark design tokens.",
      "effort": "medium"
    },
    {
      "id": "F02",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-contrast",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "medium",
      "confidence": "high",
      "summary": "The primary consent action misses minimum text contrast",
      "evidence": "Lighthouse measured the white “Allow all cookies” label on #1877f2 at 4.23:1, below the required 4.5:1 for 15px bold text.",
      "artifacts": [
        "evidence/lighthouse-findings.json"
      ],
      "suggestedFix": "Darken the primary blue or increase the text size/weight enough to satisfy WCAG contrast in every state.",
      "effort": "medium"
    },
    {
      "id": "F03",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "maximize-content-reduce-noise",
      "principleCheckId": "no-intrusive-interruptions",
      "guidanceId": "light-dismiss-a-dialog",
      "guidanceCategory": "user-experience",
      "severity": "high",
      "confidence": "high",
      "summary": "A full blocking cookie dialog obscures the entire entry experience",
      "evidence": "Mobile and desktop screenshots show an aria-modal consent layer before any interaction, dimming and blocking the login page; on mobile it consumes most of the visible page.",
      "artifacts": [
        "evidence/mobile.png"
      ],
      "suggestedFix": "Use a compact, non-obscuring consent surface where legally permissible and keep optional detail progressively disclosed.",
      "effort": "large"
    },
    {
      "id": "F04",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "maximize-content-reduce-noise",
      "principleCheckId": "semantic-dismissible-primitives",
      "guidanceId": "declarative-dialog-popover-control",
      "guidanceCategory": "user-experience",
      "severity": "medium",
      "confidence": "high",
      "summary": "The blocking dialog is custom DIV-based UI rather than a native dialog",
      "evidence": "The structure probe finds DIV role=dialog aria-modal=true, not <dialog>; focusable elements behind it appear before dialog controls in DOM focus order.",
      "artifacts": [
        "evidence/structure.json"
      ],
      "suggestedFix": "Use <dialog> with showModal(), a labelled heading, native focus containment, Escape handling, and a clear close policy.",
      "effort": "medium"
    },
    {
      "id": "F05",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "responsive-no-horizontal-scroll",
      "guidanceId": "css-layout",
      "guidanceCategory": "css",
      "severity": "high",
      "confidence": "high",
      "summary": "The m.facebook.com entry page lacks a mobile viewport declaration",
      "evidence": "At a requested 390px viewport, layout reports a 980px CSS viewport scaled to 0.398 and hasViewportMeta=false, making consent copy and footer links extremely small.",
      "artifacts": [
        "evidence/layout-mobile.json"
      ],
      "suggestedFix": "Add width=device-width, initial-scale=1 without restricting zoom, then lay out the page at the actual device width.",
      "effort": "large"
    },
    {
      "id": "F06",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "component-level-responsiveness",
      "guidanceId": "size-aware-styling",
      "guidanceCategory": "css",
      "severity": "low",
      "confidence": "high",
      "summary": "The entry components rely on page-level scaling instead of component-level responsiveness",
      "evidence": "The platform probe found zero @container rules and the 390px capture renders a 980px layout scaled down rather than adapting component geometry.",
      "artifacts": [
        "evidence/platform-probe.json"
      ],
      "suggestedFix": "Give reusable login and consent components containment and size-aware container query breakpoints, with media-query fallback where needed.",
      "effort": "small"
    },
    {
      "id": "F07",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "input-modality-aware",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "Keyboard focus is invisible on the primary login controls and footer links",
      "evidence": "The focus probe successfully focused inputs, Log in, recovery, signup, and footer links, but computed outline was none and box-shadow was none for all sampled controls.",
      "artifacts": [
        "evidence/focus-targets.json"
      ],
      "suggestedFix": "Use :focus-visible to provide a high-contrast focus ring with adequate offset on every interactive element.",
      "effort": "large"
    },
    {
      "id": "F08",
      "pathId": "login-flow",
      "url": "https://m.facebook.com",
      "principleId": "support-core-task-success",
      "principleCheckId": "primary-flow-completion",
      "guidanceId": "required-field-feedback",
      "guidanceCategory": "forms",
      "severity": "high",
      "confidence": "high",
      "summary": "Empty login submission provides no actionable response",
      "evidence": "After declining optional cookies and invoking Log in with both fields empty, the page remained unchanged with no invalid controls and no alert or live-region message.",
      "artifacts": [
        "evidence/login-validation.json"
      ],
      "suggestedFix": "Use native required constraints and keep the user on the form with field-specific, programmatically associated errors.",
      "effort": "large"
    },
    {
      "id": "F09",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "support-core-task-success",
      "principleCheckId": "clear-system-state-and-recovery",
      "guidanceId": "accessible-error-announcement",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "The primary flow does not expose validation or recovery state for missing credentials",
      "evidence": "The exercised empty-submit state produced invalid: [] and alerts: [], so users receive no state change, diagnosis, or recovery instruction.",
      "artifacts": [
        "evidence/login-validation.json"
      ],
      "suggestedFix": "Validate after interaction, announce a concise summary, focus the first invalid field, and preserve entered values.",
      "effort": "large"
    },
    {
      "id": "F10",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "good-core-web-vitals",
      "guidanceId": "performance",
      "guidanceCategory": "performance",
      "severity": "high",
      "confidence": "high",
      "summary": "The mobile authentication route paints too slowly",
      "evidence": "Lighthouse measured FCP 5.3s, LCP 7.8s, Speed Index 8.1s and performance 0.59; the raw-CDP trace independently measured FCP 4.04s and LCP 4.19s.",
      "artifacts": [
        "evidence/trace-summary.json"
      ],
      "suggestedFix": "Prioritise the LCP element, reduce document/resource latency, and remove nonessential work from the first authentication render.",
      "effort": "large"
    },
    {
      "id": "F11",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "visual-stability",
      "guidanceId": "visually-stable-font-fallbacks",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "Late layout movement and dimensionless consent images destabilise first render",
      "evidence": "The layout observer recorded CLS 0.0857 at about 2.26s; all four consent images lack a height attribute and the images probe flags missing dimensions.",
      "artifacts": [
        "evidence/layout-mobile.json"
      ],
      "suggestedFix": "Reserve image space with width and height/aspect-ratio and prevent the late consent insertion from shifting layout.",
      "effort": "medium"
    },
    {
      "id": "F12",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "efficient-resource-delivery",
      "guidanceId": "optimize-preload-priority",
      "guidanceCategory": "performance",
      "severity": "high",
      "confidence": "high",
      "summary": "The anonymous entry route ships a heavy dependency chain",
      "evidence": "The HAR records 41 requests and 2,050,669 transferred bytes, including 1.33MB of JavaScript, 324KB CSS, a 183KB font, and a parser-inserted 289KB stylesheet.",
      "artifacts": [
        "evidence/network-summary.json"
      ],
      "suggestedFix": "Split the anonymous route, inline only critical CSS, defer noncritical assets, and tune preload/fetch priorities around the LCP.",
      "effort": "large"
    },
    {
      "id": "F13",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "trim-unused-and-duplicate-code",
      "guidanceId": "identify-heavy-scripts",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "Large unused JavaScript payloads are delivered to the login route",
      "evidence": "Lighthouse’s unused-javascript audit failed with three resources while the HAR shows 24 scripts transferring 1.33MB for a simple login/consent surface.",
      "artifacts": [
        "evidence/lighthouse.json"
      ],
      "suggestedFix": "Use route-level code splitting and coverage data to remove modules not needed for anonymous login and consent.",
      "effort": "medium"
    },
    {
      "id": "F14",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-inclusive",
      "principleCheckId": "names-roles-labels",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "Authentication and consent controls contain accessibility naming/role defects",
      "evidence": "Lighthouse found a role=heading image without aria-level and an unlabeled consent checkbox; the registration probe also shows custom DIV role=button controls.",
      "artifacts": [
        "evidence/lighthouse-findings.json"
      ],
      "suggestedFix": "Use native headings/buttons/inputs and provide explicit labels and all role-required ARIA attributes.",
      "effort": "large"
    },
    {
      "id": "F15",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-inclusive",
      "principleCheckId": "sufficient-contrast",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "medium",
      "confidence": "high",
      "summary": "Consent action text has insufficient contrast",
      "evidence": "Lighthouse identifies the “Allow all cookies” text at 4.23:1 against its blue background, below 4.5:1.",
      "artifacts": [
        "evidence/lighthouse-findings.json"
      ],
      "suggestedFix": "Adjust consent button colors and test all interactive states to WCAG AA.",
      "effort": "medium"
    },
    {
      "id": "F16",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-inclusive",
      "principleCheckId": "structure-and-focus",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "Heading structure and focus treatment are incomplete",
      "evidence": "The entry structure contains no h1, uses a DIV role=main, and the focus probe finds no visible outline or shadow on sampled controls; Lighthouse also reports malformed ARIA.",
      "artifacts": [
        "evidence/structure.json"
      ],
      "suggestedFix": "Add a real page h1, semantic landmarks, native controls, modal focus containment, and consistent :focus-visible styling.",
      "effort": "large"
    },
    {
      "id": "F17",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-inclusive",
      "principleCheckId": "legible-text",
      "guidanceId": "improve-text-layout-and-legibility",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "The mobile entry view scales desktop typography down to illegible sizes",
      "evidence": "The 390px capture uses a 980px CSS viewport at 0.398 scale; the DOM reports 12px body text, rendering key consent and footer copy at roughly 4.8 CSS pixels visually.",
      "artifacts": [
        "evidence/mobile.png"
      ],
      "suggestedFix": "Use the device-width viewport and responsive type with a readable minimum size and line height.",
      "effort": "large"
    },
    {
      "id": "F18",
      "pathId": "login-flow",
      "url": "https://m.facebook.com",
      "principleId": "be-inclusive",
      "principleCheckId": "zoom-reflow-targets-and-media",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "Viewport handling prevents reliable mobile reflow and restricts zoom on a Lighthouse route",
      "evidence": "The CDP entry route has no viewport meta; Lighthouse’s redirected mobile login has user-scalable=no, initial-scale=1, maximum-scale=1.",
      "artifacts": [
        "evidence/lighthouse-findings.json"
      ],
      "suggestedFix": "Use width=device-width, initial-scale=1 and never disable pinch zoom; verify 200%/400% reflow and target sizing.",
      "effort": "large"
    },
    {
      "id": "F19",
      "pathId": "login-flow",
      "url": "https://m.facebook.com",
      "principleId": "follow-best-practices",
      "principleCheckId": "no-console-errors",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "medium",
      "confidence": "high",
      "summary": "The mobile login route throws a production JavaScript exception",
      "evidence": "Lighthouse captured TypeError: Cannot read properties of undefined (reading getElementsByTagName) in a first-party fbcdn script.",
      "artifacts": [
        "evidence/lighthouse-findings.json"
      ],
      "suggestedFix": "Fix the null/undefined state in scrollToHeader and add production error monitoring/regression coverage for anonymous login.",
      "effort": "medium"
    },
    {
      "id": "F20",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "follow-best-practices",
      "principleCheckId": "sound-document-and-assets",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "medium",
      "confidence": "high",
      "summary": "Consent images omit intrinsic height and the entry document omits key metadata",
      "evidence": "The images probe reports all four PNGs missing height; the DOM has a valid doctype/UTF-8 but no viewport or description, and CLS reached 0.0857.",
      "artifacts": [
        "evidence/images.json"
      ],
      "suggestedFix": "Add intrinsic width/height, responsive sources, and complete the document head for the actual mobile route.",
      "effort": "medium"
    },
    {
      "id": "F21",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "follow-best-practices",
      "principleCheckId": "browser-platform-hygiene",
      "guidanceId": "detect-initial-visibility-state",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "Deprecated unload listeners and bfcache blockers remain",
      "evidence": "Lighthouse reports a deprecated unload listener and four back/forward-cache failure reasons on the mobile login route.",
      "artifacts": [
        "evidence/lighthouse-findings.json"
      ],
      "suggestedFix": "Replace unload work with pagehide/visibilitychange where necessary and remove bfcache blockers.",
      "effort": "medium"
    },
    {
      "id": "F22",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-discoverable",
      "principleCheckId": "title-and-description",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "medium",
      "confidence": "high",
      "summary": "The entry route has no meta description",
      "evidence": "The DOM probe finds title “Facebook” but description=null; the raw HTML comparison also reports no meta description.",
      "artifacts": [
        "evidence/structure.json"
      ],
      "suggestedFix": "Add a concise, route-specific meta description that describes login and account creation.",
      "effort": "medium"
    },
    {
      "id": "F23",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-discoverable",
      "principleCheckId": "crawlable-and-mobile-friendly",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "high",
      "confidence": "high",
      "summary": "The canonical entry experience is not mobile-friendly at the requested URL",
      "evidence": "Links are crawlable, but the DOM and layout probes show no viewport meta and a 980px layout scaled into 390px.",
      "artifacts": [
        "evidence/layout-mobile.json"
      ],
      "suggestedFix": "Serve a device-width viewport and responsive layout consistently before redirects and consent handling.",
      "effort": "large"
    },
    {
      "id": "F24",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-discoverable",
      "principleCheckId": "canonical-and-indexing-signals",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "low",
      "confidence": "high",
      "summary": "The sitemap endpoint fails and indexing signals are inconsistent across m/www routes",
      "evidence": "The entry canonical points to en-gb.facebook.com, robots.txt is available, but /sitemap.xml returns HTTP 500.",
      "artifacts": [
        "evidence/crawl-signals.txt"
      ],
      "suggestedFix": "Return a valid sitemap index and align canonical/locale signals across m.facebook.com and www.facebook.com.",
      "effort": "small"
    },
    {
      "id": "F25",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-discoverable",
      "principleCheckId": "structured-and-shareable-metadata",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "low",
      "confidence": "high",
      "summary": "The anonymous landing route exposes no structured or social metadata",
      "evidence": "The metadata probe found no JSON-LD, microdata, hreflang, Open Graph, or description metadata on the rendered entry route.",
      "artifacts": [
        "evidence/metadata-scripts.json"
      ],
      "suggestedFix": "Add accurate Open Graph/social metadata and only the schema.org markup that matches visible content.",
      "effort": "small"
    },
    {
      "id": "F26",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-private-and-secure",
      "principleCheckId": "secure-transport-and-headers",
      "guidanceId": "security",
      "guidanceCategory": "security",
      "severity": "medium",
      "confidence": "high",
      "summary": "Security headers are strong overall but the CSP and referrer controls have gaps",
      "evidence": "HTTPS, HSTS, nosniff, X-Frame-Options and Permissions-Policy are present, but Referrer-Policy is absent and style-src allows unsafe-inline.",
      "artifacts": [
        "evidence/headers.json"
      ],
      "suggestedFix": "Set an explicit strict-origin-when-cross-origin (or stricter) Referrer-Policy and migrate inline styles to nonce/hash-based CSP.",
      "effort": "medium"
    },
    {
      "id": "F27",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-private-and-secure",
      "principleCheckId": "data-minimisation-and-third-parties",
      "guidanceId": "privacy",
      "guidanceCategory": "privacy",
      "severity": "medium",
      "confidence": "high",
      "summary": "The pre-consent route contacts Instagram and transfers substantial cross-origin resources",
      "evidence": "Before consent, the tracker/HAR evidence records an Instagram XHR plus 2.05MB classified cross-origin from Facebook/CDN origins; no known third-party tracker or cookie was found.",
      "artifacts": [
        "evidence/network-summary.json"
      ],
      "suggestedFix": "Eliminate nonessential pre-consent calls, document each cross-origin purpose, and delay optional integrations until consent.",
      "effort": "medium"
    },
    {
      "id": "F28",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-private-and-secure",
      "principleCheckId": "defensive-browser-policies",
      "guidanceId": "security",
      "guidanceCategory": "security",
      "severity": "medium",
      "confidence": "high",
      "summary": "Defensive policy coverage is incomplete",
      "evidence": "Headers show HSTS, DENY framing, nosniff and a broad Permissions-Policy, but no Referrer-Policy and CSP style-src unsafe-inline.",
      "artifacts": [
        "evidence/headers.json"
      ],
      "suggestedFix": "Add explicit referrer isolation and tighten CSP without unsafe-inline while retaining nonce-based scripts.",
      "effort": "medium"
    },
    {
      "id": "F29",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-resilient",
      "principleCheckId": "network-and-http-failure-states",
      "guidanceId": "accessible-error-announcement",
      "guidanceCategory": "accessibility",
      "severity": "medium",
      "confidence": "high",
      "summary": "The tested primary form does not present a recoverable failure state",
      "evidence": "The empty login submission generated neither native invalid state nor an ARIA alert, leaving the user with no diagnosis or retry guidance.",
      "artifacts": [
        "evidence/login-validation.json"
      ],
      "suggestedFix": "Build explicit loading/error/retry states and use native validation plus announced field errors.",
      "effort": "medium"
    },
    {
      "id": "F30",
      "pathId": "login-flow",
      "url": "https://m.facebook.com",
      "principleId": "be-trustworthy",
      "principleCheckId": "humane-error-handling",
      "guidanceId": "validate-input-after-interaction",
      "guidanceCategory": "forms",
      "severity": "high",
      "confidence": "high",
      "summary": "Missing credentials receive no humane validation feedback",
      "evidence": "After empty submission, no :invalid/aria-invalid controls and no alert/live region appeared.",
      "artifacts": [
        "evidence/login-validation.json"
      ],
      "suggestedFix": "Validate after interaction, explain how to fix each field, focus the first error, and preserve user input.",
      "effort": "large"
    },
    {
      "id": "F31",
      "pathId": "registration",
      "url": "https://m.facebook.com",
      "principleId": "be-trustworthy",
      "principleCheckId": "trustworthy-input-assistance",
      "guidanceId": "autofill-sign-in-form",
      "guidanceCategory": "forms",
      "severity": "high",
      "confidence": "high",
      "summary": "Password and registration fields disable useful autofill semantics",
      "evidence": "Login email uses autocomplete=\"username webauthn\", but password autocomplete is empty; all sampled registration inputs use autocomplete=\"off\".",
      "artifacts": [
        "evidence/registration-controls.json"
      ],
      "suggestedFix": "Use current-password, given-name, family-name, bday, email/tel, and new-password tokens as appropriate.",
      "effort": "large"
    },
    {
      "id": "F32",
      "pathId": "registration",
      "url": "https://m.facebook.com",
      "principleId": "be-trustworthy",
      "principleCheckId": "safe-commercial-and-account-flows",
      "guidanceId": "passkey-registration",
      "guidanceCategory": "security",
      "severity": "medium",
      "confidence": "high",
      "summary": "Account creation uses custom controls with weak native form semantics",
      "evidence": "Registration exposes DIV role=button submission and inputs without required constraints; sampled controls use autocomplete=off.",
      "artifacts": [
        "evidence/registration-controls.json"
      ],
      "suggestedFix": "Use a real form and submit button, native required/type semantics, autofill tokens, clear terms, and passkey-ready authentication.",
      "effort": "medium"
    },
    {
      "id": "F33",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-sustainable",
      "principleCheckId": "optimised-assets",
      "guidanceId": "deliver-optimized-decorative-images",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "Consent imagery is not delivered with modern responsive image practices",
      "evidence": "Four below-fold PNGs have no srcset, no lazy loading, no intrinsic height, and no modern format; images transfer 118KB.",
      "artifacts": [
        "evidence/images.json"
      ],
      "suggestedFix": "Use AVIF/WebP picture sources, intrinsic dimensions, srcset/sizes, and lazy loading for below-fold cards.",
      "effort": "medium"
    },
    {
      "id": "F34",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-sustainable",
      "principleCheckId": "no-wasteful-work",
      "guidanceId": "efficient-background-processing",
      "guidanceCategory": "performance",
      "severity": "high",
      "confidence": "high",
      "summary": "A simple anonymous login surface performs disproportionate work",
      "evidence": "The route transfers 2.05MB and 24 scripts; the trace records two long tasks and 184ms TBT, while Lighthouse flags unused JavaScript.",
      "artifacts": [
        "evidence/network-summary.json"
      ],
      "suggestedFix": "Create a minimal anonymous bundle and defer analytics/integrations and below-fold consent detail until needed.",
      "effort": "large"
    },
    {
      "id": "F35",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-sustainable",
      "principleCheckId": "third-party-and-media-budget",
      "guidanceId": "deprioritize-background-fetches",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "The anonymous route exceeds a reasonable cross-origin asset budget",
      "evidence": "HAR classifies 2,050,231 bytes across 32 requests as cross-origin from the m.facebook.com start URL, primarily fbcdn and www.facebook.com.",
      "artifacts": [
        "evidence/network-summary.json"
      ],
      "suggestedFix": "Set an anonymous-route transfer/request budget, normalize first-party origin accounting, and remove nonessential cross-origin dependencies.",
      "effort": "medium"
    },
    {
      "id": "F36",
      "pathId": "entry-consent",
      "url": "https://m.facebook.com",
      "principleId": "be-memory-efficient",
      "principleCheckId": "bounded-footprint",
      "guidanceId": "performance",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "The static first-run route has a large in-memory footprint",
      "evidence": "The baseline heap summary contains 860,566 nodes and 43.9MB self size before meaningful interaction, disproportionate to a login and consent surface.",
      "artifacts": [
        "evidence/heap-baseline.json"
      ],
      "suggestedFix": "Reduce the anonymous component/runtime graph, lazy-initialise consent detail, and track heap/node budgets in regression tests.",
      "effort": "medium"
    }
  ],
  "taskList": [
    {
      "id": "T01",
      "title": "Restore true mobile reflow, zoom, and legible typography",
      "priority": 1,
      "findingIds": [
        "F05",
        "F06",
        "F07",
        "F18",
        "F23"
      ],
      "guidanceId": "css-layout",
      "status": "open"
    },
    {
      "id": "T02",
      "title": "Make keyboard focus, semantics, and labels robust",
      "priority": 2,
      "findingIds": [
        "F07",
        "F14",
        "F15",
        "F16",
        "F17",
        "F18"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T03",
      "title": "Return humane validation and recovery from authentication errors",
      "priority": 3,
      "findingIds": [
        "F08",
        "F09",
        "F29",
        "F30"
      ],
      "guidanceId": "accessible-error-announcement",
      "status": "open"
    },
    {
      "id": "T04",
      "title": "Cut anonymous-route JavaScript, CSS, font, and dependency weight",
      "priority": 4,
      "findingIds": [
        "F10",
        "F11",
        "F12",
        "F13",
        "F34",
        "F36"
      ],
      "guidanceId": "performance",
      "status": "open"
    },
    {
      "id": "T05",
      "title": "Replace the blocking custom consent overlay with a focused semantic dialog",
      "priority": 5,
      "findingIds": [
        "F03",
        "F04"
      ],
      "guidanceId": "declarative-dialog-popover-control",
      "status": "open"
    },
    {
      "id": "T06",
      "title": "Respect theme and contrast preferences",
      "priority": 6,
      "findingIds": [
        "F01",
        "F02"
      ],
      "guidanceId": "dark-mode",
      "status": "open"
    },
    {
      "id": "T07",
      "title": "Fix account autofill, native form semantics, and passkey readiness",
      "priority": 7,
      "findingIds": [
        "F31",
        "F32"
      ],
      "guidanceId": "autofill-sign-in-form",
      "status": "open"
    },
    {
      "id": "T08",
      "title": "Tighten CSP/referrer policy and minimise pre-consent requests",
      "priority": 8,
      "findingIds": [
        "F26",
        "F27",
        "F28"
      ],
      "guidanceId": "security",
      "status": "open"
    },
    {
      "id": "T09",
      "title": "Complete metadata, canonical, sitemap, and social discovery signals",
      "priority": 9,
      "findingIds": [
        "F22",
        "F23",
        "F24",
        "F25"
      ],
      "guidanceId": "html",
      "status": "open"
    },
    {
      "id": "T10",
      "title": "Optimise and dimension consent imagery",
      "priority": 10,
      "findingIds": [
        "F11",
        "F20",
        "F33"
      ],
      "guidanceId": "deliver-optimized-decorative-images",
      "status": "open"
    },
    {
      "id": "T11",
      "title": "Remove production exceptions, deprecated unload work, and bfcache blockers",
      "priority": 11,
      "findingIds": [
        "F19",
        "F20",
        "F21"
      ],
      "guidanceId": "html",
      "status": "open"
    }
  ],
  "budget": {
    "wallClockSeconds": 900,
    "pathCount": 5,
    "auditPasses": 1
  },
  "agent": "pi",
  "runId": "2026-07-26T21-59-19-108Z"
}
