anvilsign in

collin/anvil

BoardRenderedSource

1# Todo
2
3
4# Backlog
5
6
7- [ ] pull requests (gix merge)
8- [ ] pull mirror (maybe): a repo that virtually mirrors a GitHub repo
9 - just displays it here — periodically fetched, read-only on the anvil side
10
11- [ ] richer file editing: a real markdown editor with a live render preview
12 (reuse `render_markdown`) before committing
13- [ ] webhooks (mind the SSRF item in `docs/untrusted-mode.md`)
14- [ ] attachment reclaim: an orphan sweep (delete attachments no committed file
15 references) and/or a per-attachment delete action — the recourse once a repo
16 hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy
17 (tip-only vs any-ref), so it wants its own design pass
18- [ ] remove a repo's attachment + artifact dirs on repo delete — blocked: there
19 is no repo-delete path yet (only the create-rollback uses it)
20- [ ] admin usage: per-repo drill-down, and a cheap cached/periodic variant if
21 the on-demand disk walk gets slow on large instances
22- [ ] API tokens: a `write` scope (would need CSRF-exempt write paths) and
23 `last_used_at` tracking