anvilsign in

collin/anvil

BoardRenderedSource

1# Todo
2
3- [ ] pull mirror (maybe): a repo that virtually mirrors a GitHub repo
4 - just displays it here — periodically fetched, read-only on the anvil side
5- [ ] pull requests (gix merge)
6- [ ] webhooks (mind the SSRF item in `docs/untrusted-mode.md`)
7- [ ] richer file editing: a real markdown editor with a live render preview
8 (reuse `render_markdown`) before committing
9- [ ] attachment reclaim: an orphan sweep (delete attachments no committed file
10 references) and/or a per-attachment delete action — the recourse once a repo
11 hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy
12 (tip-only vs any-ref), so it wants its own design pass
13- [ ] remove a repo's attachment + artifact dirs on repo delete — blocked: there
14 is no repo-delete path yet (only the create-rollback uses it)
15- [ ] admin usage: per-repo drill-down, and a cheap cached/periodic variant if
16 the on-demand disk walk gets slow on large instances
17- [ ] API tokens: a `write` scope (would need CSRF-exempt write paths) and
18 `last_used_at` tracking