collin/anvil
5c0c3dfd224d7ff069a99a59b7d4d2a14e87dac4 / TODO.md
| 1 | # Todo |
| 2 | |
| 3 | |
| 4 | # Backlog |
| 5 | |
| 6 | |
| 7 | - [ ] pull requests (gix merge) |
| 8 | - [ ] pull mirror (maybe): a repo that virtually mirrors a GitHub repo |
| 9 | - just displays it here — periodically fetched, read-only on the anvil side |
| 10 | |
| 11 | - [ ] richer file editing: a real markdown editor with a live render preview |
| 12 | (reuse `render_markdown`) before committing |
| 13 | - [ ] webhooks (mind the SSRF item in `docs/untrusted-mode.md`) |
| 14 | - [ ] attachment reclaim: an orphan sweep (delete attachments no committed file |
| 15 | references) and/or a per-attachment delete action — the recourse once a repo |
| 16 | hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy |
| 17 | (tip-only vs any-ref), so it wants its own design pass |
| 18 | - [ ] remove a repo's attachment + artifact dirs on repo delete — blocked: there |
| 19 | is no repo-delete path yet (only the create-rollback uses it) |
| 20 | - [ ] admin usage: per-repo drill-down, and a cheap cached/periodic variant if |
| 21 | the on-demand disk walk gets slow on large instances |
| 22 | - [ ] API tokens: a `write` scope (would need CSRF-exempt write paths) and |
| 23 | `last_used_at` tracking |