Parent phase: #235
Parent roadmap: #127
Problem
The extension must make role boundaries impossible to miss: maintainers can see private review context, contributors/miners see safe contributor context, and public/copied snippets remain sanitized.
Acceptance criteria
- Role detection is explicit and covered for maintainer, contributor/miner, unauthenticated, unsupported repo, and API-error states.
- Private panels cannot be rendered in public or unauthenticated states.
- Copyable/public snippets pass the same sanitizer rules as GitHub App output.
Validation expected
- Tests cover role-based rendering and sanitizer behavior.
- Screenshots or recording show each role/state boundary.
UI evidence gate
Any visible web, browser-extension, or GitHub-overlay change must include maintainer-reviewable screenshots or a short recording covering the changed states. A checked template box without actual visual evidence is not enough.
Public-output safety criteria
- Public text is sanitized before reaching GitHub comments, issue bodies, PR bodies, extension-visible public panels, or copied public snippets.
- Tests cover forbidden wallet/hotkey, reward-estimate, trust-score, public-score-prediction, private-reviewability, private-scoreability, and farming-language leakage.
Cross-cutting acceptance criteria
- Preserve the repo quality gate:
npm run test:ci, 97%+ global coverage, and the local branch coverage target for touched code.
- Keep public/private boundaries explicit. Public GitHub output must not expose wallets, hotkeys, reward estimates, raw trust scores, public score predictions, private reviewability, private scoreability context, or farming language.
- Add/update focused tests for the changed behavior instead of relying on green checks alone.
Parent phase: #235
Parent roadmap: #127
Problem
The extension must make role boundaries impossible to miss: maintainers can see private review context, contributors/miners see safe contributor context, and public/copied snippets remain sanitized.
Acceptance criteria
Validation expected
UI evidence gate
Any visible web, browser-extension, or GitHub-overlay change must include maintainer-reviewable screenshots or a short recording covering the changed states. A checked template box without actual visual evidence is not enough.
Public-output safety criteria
Cross-cutting acceptance criteria
npm run test:ci, 97%+ global coverage, and the local branch coverage target for touched code.