collin/anvil
2f35cebbbbd354d178741ac6c375a3f1dd547905 / TODO.md
| 1 | # Todo |
| 2 | |
| 3 | ## Add the ability to delete a repo |
| 4 | |
| 5 | Deleted no reboux should only be done through the settings.Menu of a repo must be the.Repo owner?And there should be some sort of confirmation dialogue that prevents it from being done on accident.Such as typing in the name of the repo.When you try to delete it |
| 6 | |
| 7 | |
| 8 | # Backlog |
| 9 | |
| 10 | |
| 11 | - [ ] agent sessions, next milestones (docs/agent-sessions.md): |
| 12 | - a real checkout: the container clones from anvil's smart-HTTP endpoint and |
| 13 | pushes `agent/<id>` back. Needs a session-scoped push credential, which |
| 14 | does not exist (tokens are read-only, Bearer only on GET/HEAD) |
| 15 | - ref-scope that credential to `refs/heads/agent/*` — needs a ref filter in |
| 16 | receive-pack. Until it lands a session credential could write `main` |
| 17 | - trigger surfaces: a start button on a TODO item, an issue, a red CI run |
| 18 | - rate limiting, so automated pushes can't queue sessions endlessly once |
| 19 | triggers exist (`max_concurrent` bounds concurrency, not churn) |
| 20 | - a finished session's transcript rendered on its page (it is already on |
| 21 | disk under `sessions/<id>.log`; nothing reads it back yet) |
| 22 | |
| 23 | - [ ] pull requests (gix merge) |
| 24 | - [ ] pull mirror (maybe): a repo that virtually mirrors a GitHub repo |
| 25 | - just displays it here — periodically fetched, read-only on the anvil side |
| 26 | |
| 27 | - [ ] richer file editing: a real markdown editor with a live render preview |
| 28 | (reuse `render_markdown`) before committing |
| 29 | - [ ] webhooks (mind the SSRF item in `docs/untrusted-mode.md`) |
| 30 | - [ ] attachment reclaim: an orphan sweep (delete attachments no committed file |
| 31 | references) and/or a per-attachment delete action — the recourse once a repo |
| 32 | hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy |
| 33 | (tip-only vs any-ref), so it wants its own design pass |
| 34 | - [ ] remove a repo's attachment + artifact dirs on repo delete — blocked: there |
| 35 | is no repo-delete path yet (only the create-rollback uses it) |
| 36 | - [ ] admin usage: per-repo drill-down, and a cheap cached/periodic variant if |
| 37 | the on-demand disk walk gets slow on large instances |
| 38 | - [ ] periodic disk usage cache: run `usage::compute()` on a timer (e.g., hourly) |
| 39 | and store the result so the admin dashboard doesn't block on disk walks |
| 40 | - [ ] repository preview images: extract the first "real" image (>few hundred px) |
| 41 | from README.md on a periodic scan, cache the attachment hash, and display in |
| 42 | repo listings for visual browsing |
| 43 | - [ ] API tokens: a `write` scope (would need CSRF-exempt write paths) and |
| 44 | `last_used_at` tracking |
| 45 | - [ ] single sign-on follow-ups (docs/oidc.md): silent renewal |
| 46 | (`prompt=none` on a short local session, which is what makes revoking an SSO |
| 47 | session propagate here), an admin view of who is linked to which `sub`, and |
| 48 | unlinking an account from the settings page |
| 49 | - [ ] secrets follow-ups (docs/secrets.md): authenticate `anvild secret` with an |
| 50 | ssh signature instead of the account password; per-step rather than per- |
| 51 | pipeline scoping; `ssh-rsa` recipients (needs an RSA-OAEP branch in both the |
| 52 | Rust and the browser halves); drop a repo's secrets when repo delete lands |