- POST /api/v1/reviews (one per chat_id, UNIQUE)
- GET /api/v1/users/:id/reviews (public list)
- GET /api/v1/users/:id/stats (rating_avg, count)
- migration 0004: reviews (rating 1-5, anonymous flag), user_stats aggregate
- only chat participants can review; reviewed_id is other party