collin/anvil
5c0c3dfd224d7ff069a99a59b7d4d2a14e87dac4 / TODO.md
Backlog8 open
- pull requests (gix merge)
pull mirror (maybe): a repo that virtually mirrors a GitHub repo
- just displays it here — periodically fetched, read-only on the anvil side
richer file editing: a real markdown editor with a live render preview
(reuse
render_markdown) before committing- webhooks (mind the SSRF item in
docs/untrusted-mode.md) attachment reclaim: an orphan sweep (delete attachments no committed file
references) and/or a per-attachment delete action — the recourse once a repo hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy (tip-only vs any-ref), so it wants its own design pass
remove a repo's attachment + artifact dirs on repo delete — blocked: there
is no repo-delete path yet (only the create-rollback uses it)
admin usage: per-repo drill-down, and a cheap cached/periodic variant if
the on-demand disk walk gets slow on large instances
API tokens: a
writescope (would need CSRF-exempt write paths) andlast_used_attracking