anvilsign in

collin/anvil

BoardRenderedSource

Backlog12 open

  1. agent sessions, next milestones (docs/agent-sessions.md):
    • a real checkout: the container clones from anvil's smart-HTTP endpoint and pushes agent/<id> back. Needs a session-scoped push credential, which does not exist (tokens are read-only, Bearer only on GET/HEAD)
    • ref-scope that credential to refs/heads/agent/* — needs a ref filter in receive-pack. Until it lands a session credential could write main
    • trigger surfaces: a start button on a TODO item, an issue, a red CI run
    • rate limiting, so automated pushes can't queue sessions endlessly once triggers exist (max_concurrent bounds concurrency, not churn)
    • a finished session's transcript rendered on its page (it is already on disk under sessions/<id>.log; nothing reads it back yet)
  2. pull requests (gix merge)
  3. pull mirror (maybe): a repo that virtually mirrors a GitHub repo
    • just displays it here — periodically fetched, read-only on the anvil side
  4. richer file editing: a real markdown editor with a live render preview

    (reuse render_markdown) before committing

  5. webhooks (mind the SSRF item in docs/untrusted-mode.md)
  6. attachment reclaim: an orphan sweep (delete attachments no committed file

    references) and/or a per-attachment delete action — the recourse once a repo hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy (tip-only vs any-ref), so it wants its own design pass

  7. admin usage: per-repo drill-down, and a cheap cached/periodic variant if

    the on-demand disk walk gets slow on large instances

  8. periodic disk usage cache: run usage::compute() on a timer (e.g., hourly)

    and store the result so the admin dashboard doesn't block on disk walks

  9. repository preview images: extract the first "real" image (>few hundred px)

    from README.md on a periodic scan, cache the attachment hash, and display in repo listings for visual browsing

  10. API tokens: a write scope (would need CSRF-exempt write paths) and

    last_used_at tracking

  11. single sign-on follow-ups (docs/oidc.md): silent renewal

    (prompt=none on a short local session, which is what makes revoking an SSO session propagate here), an admin view of who is linked to which sub, and unlinking an account from the settings page

  12. secrets follow-ups (docs/secrets.md): authenticate anvild secret with an

    ssh signature instead of the account password; per-step rather than per- pipeline scoping; ssh-rsa recipients (needs an RSA-OAEP branch in both the Rust and the browser halves)