collin/anvil
12249ca50f6643c02c992530842d3d16b9cf2266 / TODO.md
Todo
-
pull mirror (maybe): a repo that virtually mirrors a GitHub repo
- just displays it here — periodically fetched, read-only on the anvil side
- pull requests (gix merge)
-
webhooks (mind the SSRF item in
docs/untrusted-mode.md) -
richer file editing: a real markdown editor with a live render preview
(reuse
render_markdown) before committing - attachment reclaim: an orphan sweep (delete attachments no committed file references) and/or a per-attachment delete action — the recourse once a repo hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy (tip-only vs any-ref), so it wants its own design pass
- remove a repo's attachment + artifact dirs on repo delete — blocked: there is no repo-delete path yet (only the create-rollback uses it)
- admin usage: per-repo drill-down, and a cheap cached/periodic variant if the on-demand disk walk gets slow on large instances
-
API tokens: a
writescope (would need CSRF-exempt write paths) andlast_used_attracking