A client which is on the same network as a server can request data from the server, and the server chooses how to reply. The internet is just a really big network, so for an internet-facing computer the assumption is that anyone can request data. The analogy of the request-response process to physical space isn't--as the judge claimed--someone entering a building, but rather someone asking permission to enter the building. Asking permission to enter a bank with a shotgun is very different from actually entering and is not itself a crime (as far as I'm aware).
Every interaction between the client and server begins as a request from the client. If the server replies "yes, have some data" it's nonsensical that this could be construed as gaining unauthorized access, as Facebook claims. Ultimately, Facebook still controls access to its servers; it just hasn't figured out a good policy for denying certain requests. This is a technical problem which should be solved through technical means (e.g. blocking IP addresses) or by changing its terms of service with its users.
Unfortunately, rather than solving the problem itself, Facebook has convinced the federal government to work on its behalf through an especially blunt weapon known as the CFAA. This risks changing the entire legal framework in which everyone else is required to operate. Technology moves much faster than the laws governing it, so we may not appreciate the full impact of this decision until later. That should give even proponents some pause.