anvilsign in

collin/anvil

BoardRenderedSource

1# Todo
2
3
4# Backlog
5
6
7- [ ] agent sessions, next milestones (docs/agent-sessions.md):
8 - a real checkout: the container clones from anvil's smart-HTTP endpoint and
9 pushes `agent/<id>` back. Needs a session-scoped push credential, which
10 does not exist (tokens are read-only, Bearer only on GET/HEAD)
11 - ref-scope that credential to `refs/heads/agent/*` — needs a ref filter in
12 receive-pack. Until it lands a session credential could write `main`
13 - trigger surfaces: a start button on a TODO item, an issue, a red CI run
14 - rate limiting, so automated pushes can't queue sessions endlessly once
15 triggers exist (`max_concurrent` bounds concurrency, not churn)
16 - a finished session's transcript rendered on its page (it is already on
17 disk under `sessions/<id>.log`; nothing reads it back yet)
18
19- [ ] pull requests (gix merge)
20- [ ] pull mirror (maybe): a repo that virtually mirrors a GitHub repo
21 - just displays it here — periodically fetched, read-only on the anvil side
22
23- [ ] richer file editing: a real markdown editor with a live render preview
24 (reuse `render_markdown`) before committing
25- [ ] webhooks (mind the SSRF item in `docs/untrusted-mode.md`)
26- [ ] attachment reclaim: an orphan sweep (delete attachments no committed file
27 references) and/or a per-attachment delete action — the recourse once a repo
28 hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy
29 (tip-only vs any-ref), so it wants its own design pass
30- [ ] admin usage: per-repo drill-down, and a cheap cached/periodic variant if
31 the on-demand disk walk gets slow on large instances
32- [ ] periodic disk usage cache: run `usage::compute()` on a timer (e.g., hourly)
33 and store the result so the admin dashboard doesn't block on disk walks
34- [ ] repository preview images: extract the first "real" image (>few hundred px)
35 from README.md on a periodic scan, cache the attachment hash, and display in
36 repo listings for visual browsing
37- [ ] API tokens: a `write` scope (would need CSRF-exempt write paths) and
38 `last_used_at` tracking
39- [ ] single sign-on follow-ups (docs/oidc.md): silent renewal
40 (`prompt=none` on a short local session, which is what makes revoking an SSO
41 session propagate here), an admin view of who is linked to which `sub`, and
42 unlinking an account from the settings page
43- [ ] secrets follow-ups (docs/secrets.md): authenticate `anvild secret` with an
44 ssh signature instead of the account password; per-step rather than per-
45 pipeline scoping; `ssh-rsa` recipients (needs an RSA-OAEP branch in both the
46 Rust and the browser halves)