Skip to content

Add separate GitHub Billing accounts with verified monthly spend #104

Description

@HemSoft

Add separate GitHub Billing accounts with verified monthly spend

Parent and priority

HemSoft/codexbar#70

P1 after native auth and monetary results. This is a planning issue, held out of automation with no-agent until its prerequisites and provider decisions are ready.

Verified gap

Windows Copilot billing is not the iOS GitHub Billing provider. The latter monitors a selected personal or organization owner across GitHub products. Issue HemSoft/codexbar#79 preserves Copilot behavior but does not add this separate provider.

Comparison uses iOS commit 8ebadd77becafb53342ef185202c2162ffa84bd7 and Windows commit 556322132cc60a38e061a329567c18ae84d30f20. Checked the full open and closed Windows issue list before filing. Upstream implementation is evidence of behavior, not proof of Windows or live-provider verification.

Acceptance criteria

  • Add a distinct GitHub Billing provider and browser sign-in flow with explicit personal or organization owner selection. Store credentials and monitored-owner identity separately from Copilot.
  • Verify user and owner access before saving. Account discovery must not imply that every organization member can read billing. Reauthentication, cancellation, owner changes, removal, and persistence failures preserve identity boundaries.
  • Read the selected owner's current billing period with bounded pagination. Display gross charges, discounts, net spend, and per-product or SKU quantities with source unit-price precision. Never substitute Copilot-only usage for owner-wide billing.
  • Require complete consistent currency evidence, using documented GitHub USD semantics only when the API supplies no currency. Conflicting or invalid evidence suppresses monetary values instead of relabeling them.
  • Show month-end spend projections only with a verified current billing month and sufficient inputs. Partial data and permission, endpoint, plan, or rate-limit failures remain visible without inventing totals.
  • Explain requested permissions before authorization. Use read-only billing, profile, organization-plan, and repository-visibility operations only. Billing authorization must never broaden or replace a saved Copilot credential.
  • Record human approval of the Windows OAuth registration, redirect configuration, and necessary scopes before release. Do not transplant bundled iOS client credentials into Windows.

Tests and verification

Mock personal and organization endpoints, pagination, billing-month boundaries, currency conflicts, partial results, precise rates, projections, permissions, token isolation, renewal races, and save failures. Include account-selection and reconnect journeys. Live comparison with the owner's GitHub billing page is a separate release verification step.

Boundaries

This issue delivers auth and monetary tracking end to end. Included-product allowance bars and organization budget semantics are a separate dependent issue. The iOS scope combination repo/admin:org/user is broad and must be evaluated for the Windows implementation rather than adopted without review.

Dependencies

Evidence

Validation gates

Implementation must pass dotnet build with zero warnings, dotnet format --verify-no-changes, dotnet test, and dotnet list package --vulnerable. Coverage must meet or exceed the current repository threshold using dotnet test --collect:"XPlat Code Coverage" --settings src/CodexBar.Core.Tests/coverage.runsettings; exclude generated *.g.cs and GeneratedRegex output as required by AGENTS.md. Validate changed Markdown.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:human-requiredFix exceeds safe automation boundary — human must own thisenhancementNew feature or requestfeature-requestRequested feature or product enhancementno-agentExclude this issue from autonomous processingrisk:highHigh-risk: auth, payments, data migrationssource:manualManually created by developer

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions