> You might ask why the Messenger API expects a JSON string inside a JSON string inside a JSON string inside an HTML form. You would have a very good question.
Probably multiple layers of tooling and encapsulation to get to the real backend, or just unpaid tech debt.
Also, first the author discovers a GraphQL endpoint. I thought great, just introspect the schema instead of blindly poking around!
But no, the GraphQL API seems to only be used to transfer project LightSpeed payloads which are server generated JS snippets meant to be blindly executed to update the UI. Rough.. I know GraphQL originates at Facebook but I don't think that was the intended usage...
Also, the author's python script seems to be opening a new session on every invocation. This might have triggered the account suspension, since login endpoints are certainly amongst the most heavily monitored for suspicious behavior.