Background
Browser extension auth is a sensitive boundary. The extension must not store GitHub PATs or leak Gittensory sessions.
Goal
Harden extension auth storage and session refresh.
Current Behavior
No extension auth model exists yet.
Desired Behavior
The extension uses Gittensory session tokens safely and supports logout, expiry, and revoked-session handling.
Implementation Requirements
- Use browser extension storage APIs appropriately.
- Do not store GitHub PATs.
- Support logout and local state clearing.
- Handle expired/revoked Gittensory sessions.
- Document threat model and permission boundaries.
Public/Private Output Boundaries
Public GitHub output must never include wallets, hotkeys, payout/reward estimates, raw trust scores, public score estimates, private reviewability, private scoreability context, or farming language. Private API/MCP/control-panel surfaces may show authenticated scoreability, blockers, projections, and evidence, but must not claim guaranteed payout outcomes.
Acceptance Criteria
- No GitHub PAT storage.
- Session tokens are stored using browser extension storage APIs.
- Logout clears local state.
- Tests cover expired/revoked sessions.
Testing Requirements
npm run test:ci must pass.
- Global coverage must remain at or above 97% for lines, statements, functions, and branches.
- Aim for 98%+ branch coverage locally.
- Add tests for every new branch, fallback path, sanitizer rule, and regression.
- Add invariant/property-style tests when behavior depends on sorting, gating, scoring, source-upload safety, public/private boundaries, or telemetry privacy.
- MCP/local tooling must prove source contents are not uploaded when local metadata is involved.
- Public GitHub output must be tested against forbidden language: wallet, hotkey, raw trust score, payout, reward estimate, farming, private reviewability, and public score estimate.
Background
Browser extension auth is a sensitive boundary. The extension must not store GitHub PATs or leak Gittensory sessions.
Goal
Harden extension auth storage and session refresh.
Current Behavior
No extension auth model exists yet.
Desired Behavior
The extension uses Gittensory session tokens safely and supports logout, expiry, and revoked-session handling.
Implementation Requirements
Public/Private Output Boundaries
Public GitHub output must never include wallets, hotkeys, payout/reward estimates, raw trust scores, public score estimates, private reviewability, private scoreability context, or farming language. Private API/MCP/control-panel surfaces may show authenticated scoreability, blockers, projections, and evidence, but must not claim guaranteed payout outcomes.
Acceptance Criteria
Testing Requirements
npm run test:cimust pass.