anvilsign in

collin/anvil

BoardRenderedSource

1# Todo
2
3## ability to link to deployed / live site
4
5## agent view, we have list of repos what about list of agents
6
7# Backlog
8
9
10- [ ] agent sessions, next milestones (docs/agent-sessions.md):
11 - a real checkout: the container clones from anvil's smart-HTTP endpoint and
12 pushes `agent/<id>` back. Needs a session-scoped push credential, which
13 does not exist (tokens are read-only, Bearer only on GET/HEAD)
14 - ref-scope that credential to `refs/heads/agent/*` — needs a ref filter in
15 receive-pack. Until it lands a session credential could write `main`
16 - trigger surfaces: a start button on a TODO item, an issue, a red CI run
17 - rate limiting, so automated pushes can't queue sessions endlessly once
18 triggers exist (`max_concurrent` bounds concurrency, not churn)
19 - a finished session's transcript rendered on its page (it is already on
20 disk under `sessions/<id>.log`; nothing reads it back yet)
21
22- [ ] pull requests (gix merge)
23- [ ] pull mirror (maybe): a repo that virtually mirrors a GitHub repo
24 - just displays it here — periodically fetched, read-only on the anvil side
25
26- [ ] richer file editing: a real markdown editor with a live render preview
27 (reuse `render_markdown`) before committing
28- [ ] webhooks (mind the SSRF item in `docs/untrusted-mode.md`)
29- [ ] attachment reclaim: an orphan sweep (delete attachments no committed file
30 references) and/or a per-attachment delete action — the recourse once a repo
31 hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy
32 (tip-only vs any-ref), so it wants its own design pass
33- [ ] admin usage: per-repo drill-down, and a cheap cached/periodic variant if
34 the on-demand disk walk gets slow on large instances
35- [ ] periodic disk usage cache: run `usage::compute()` on a timer (e.g., hourly)
36 and store the result so the admin dashboard doesn't block on disk walks
37- [ ] repository preview images: extract the first "real" image (>few hundred px)
38 from README.md on a periodic scan, cache the attachment hash, and display in
39 repo listings for visual browsing
40- [ ] API tokens: a `write` scope (would need CSRF-exempt write paths) and
41 `last_used_at` tracking
42- [ ] single sign-on follow-ups (docs/oidc.md): silent renewal
43 (`prompt=none` on a short local session, which is what makes revoking an SSO
44 session propagate here), an admin view of who is linked to which `sub`, and
45 unlinking an account from the settings page
46- [ ] secrets follow-ups (docs/secrets.md): authenticate `anvild secret` with an
47 ssh signature instead of the account password; per-step rather than per-
48 pipeline scoping; `ssh-rsa` recipients (needs an RSA-OAEP branch in both the
49 Rust and the browser halves)