anvilsign in

collin/anvil

BoardRenderedSource

Todo1 open

  1. Add the ability to delete a repo

    Deleted no reboux should only be done through the settings.Menu of a repo must be the.Repo owner?And there should be some sort of confirmation dialogue that prevents it from being done on accident.Such as typing in the name of the repo.When you try to delete it

Backlog12 open

  1. pull requests (gix merge)
  2. pull mirror (maybe): a repo that virtually mirrors a GitHub repo
    • just displays it here — periodically fetched, read-only on the anvil side
  3. richer file editing: a real markdown editor with a live render preview

    (reuse render_markdown) before committing

  4. webhooks (mind the SSRF item in docs/untrusted-mode.md)
  5. attachment reclaim: an orphan sweep (delete attachments no committed file

    references) and/or a per-attachment delete action — the recourse once a repo hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy (tip-only vs any-ref), so it wants its own design pass

  6. remove a repo's attachment + artifact dirs on repo delete — blocked: there

    is no repo-delete path yet (only the create-rollback uses it)

  7. admin usage: per-repo drill-down, and a cheap cached/periodic variant if

    the on-demand disk walk gets slow on large instances

  8. periodic disk usage cache: run usage::compute() on a timer (e.g., hourly)

    and store the result so the admin dashboard doesn't block on disk walks

  9. repository preview images: extract the first "real" image (>few hundred px)

    from README.md on a periodic scan, cache the attachment hash, and display in repo listings for visual browsing

  10. API tokens: a write scope (would need CSRF-exempt write paths) and

    last_used_at tracking

  11. passkey follow-ups (docs/passkeys.md): conditional UI (autofill-style

    sign-in), and a warning before removing the last passkey on a password-less-by-preference account

  12. secrets follow-ups (docs/secrets.md): authenticate anvild secret with an

    ssh signature instead of the account password; per-step rather than per- pipeline scoping; ssh-rsa recipients (needs an RSA-OAEP branch in both the Rust and the browser halves); drop a repo's secrets when repo delete lands