Social Publishing & Product Automation

Turn approved products into reviewable social drafts, keep privacy checks in front of publishing, and connect one selected Development provider through the protected OAuth acceptance lane.

Admin-only explanatory illustration of reviewed content, privacy/preflight review, and explicit publish.
Admin-only explanatory illustration. It is not publication evidence and is never used on product pages, social posts, Open Graph cards, or structured data.

Build 85 provider prerequisites

Public policy pages and exact callback URLs

The secure OAuth lifecycle is implemented. A real authorization response is accepted only on the Development Preview when the explicit operator switch and exactly one selected social provider agree. Production OAuth and all provider publication remain closed.

Pinterest verification: p:domain_verify is included in the head of every HTML page, including the home page.

Connection guide

What “connected” means

A pixel is tracking, not publishing. Meta Pixel/CAPI, Pinterest Tag, TikTok Pixel, and Google/YouTube tags measure visits and conversions. Organic publishing requires a provider developer app, secure OAuth authorization, intended-account verification, reviewed media/copy, and explicit human approval. Provider secrets remain in Cloudflare; they never belong in product forms, Git, browser JavaScript, or plaintext D1 fields.

How a new product becomes a social draft

  1. Product is saved as Active and Approved/Published, with a usable product image.
  2. When “Create a social draft” is enabled, the app creates one idempotent draft linked to that product.
  3. Open the queue to review copy, media, platform choices, UTM link, duplicate warning, and Social Media Privacy Guard result.
  4. Explicitly mark the queue item ready + approved only after privacy/public-media review is satisfied.
  5. The Build 85 OAuth panel may then show the evidence as ready for a future controlled publication acceptance. It still provides no provider Publish action.

Important: Automatic drafting is enabled only by an admin setting. Automatic publishing remains deliberately unavailable because every final post can expose names, addresses, private workshop details, customer information, copyright-protected material, or an unfinished product claim.