collin/anvil
02f1ec0bc18ffbfb9bd6c637c25a4e9f80388433 / TODO.md
| 1 | # Todo |
| 2 | |
| 3 | |
| 4 | # Backlog |
| 5 | |
| 6 | |
| 7 | - [ ] agent sessions, next milestones (docs/agent-sessions.md): |
| 8 | - a real checkout: the container clones from anvil's smart-HTTP endpoint and |
| 9 | pushes `agent/<id>` back. Needs a session-scoped push credential, which |
| 10 | does not exist (tokens are read-only, Bearer only on GET/HEAD) |
| 11 | - ref-scope that credential to `refs/heads/agent/*` — needs a ref filter in |
| 12 | receive-pack. Until it lands a session credential could write `main` |
| 13 | - trigger surfaces: a start button on a TODO item, an issue, a red CI run |
| 14 | - rate limiting, so automated pushes can't queue sessions endlessly once |
| 15 | triggers exist (`max_concurrent` bounds concurrency, not churn) |
| 16 | - a finished session's transcript rendered on its page (it is already on |
| 17 | disk under `sessions/<id>.log`; nothing reads it back yet) |
| 18 | |
| 19 | - [ ] pull requests (gix merge) |
| 20 | - [ ] pull mirror (maybe): a repo that virtually mirrors a GitHub repo |
| 21 | - just displays it here — periodically fetched, read-only on the anvil side |
| 22 | |
| 23 | - [ ] richer file editing: a real markdown editor with a live render preview |
| 24 | (reuse `render_markdown`) before committing |
| 25 | - [ ] webhooks (mind the SSRF item in `docs/untrusted-mode.md`) |
| 26 | - [ ] attachment reclaim: an orphan sweep (delete attachments no committed file |
| 27 | references) and/or a per-attachment delete action — the recourse once a repo |
| 28 | hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy |
| 29 | (tip-only vs any-ref), so it wants its own design pass |
| 30 | - [ ] admin usage: per-repo drill-down, and a cheap cached/periodic variant if |
| 31 | the on-demand disk walk gets slow on large instances |
| 32 | - [ ] periodic disk usage cache: run `usage::compute()` on a timer (e.g., hourly) |
| 33 | and store the result so the admin dashboard doesn't block on disk walks |
| 34 | - [ ] repository preview images: extract the first "real" image (>few hundred px) |
| 35 | from README.md on a periodic scan, cache the attachment hash, and display in |
| 36 | repo listings for visual browsing |
| 37 | - [ ] API tokens: a `write` scope (would need CSRF-exempt write paths) and |
| 38 | `last_used_at` tracking |
| 39 | - [ ] single sign-on follow-ups (docs/oidc.md): silent renewal |
| 40 | (`prompt=none` on a short local session, which is what makes revoking an SSO |
| 41 | session propagate here), an admin view of who is linked to which `sub`, and |
| 42 | unlinking an account from the settings page |
| 43 | - [ ] secrets follow-ups (docs/secrets.md): authenticate `anvild secret` with an |
| 44 | ssh signature instead of the account password; per-step rather than per- |
| 45 | pipeline scoping; `ssh-rsa` recipients (needs an RSA-OAEP branch in both the |
| 46 | Rust and the browser halves) |