anvilsign in

collin/anvil

BoardRenderedSource

Todo

Add the ability to delete a repo

Deleted no reboux should only be done through the settings.Menu of a repo must be the.Repo owner?And there should be some sort of confirmation dialogue that prevents it from being done on accident.Such as typing in the name of the repo.When you try to delete it

Backlog

  • pull requests (gix merge)

  • pull mirror (maybe): a repo that virtually mirrors a GitHub repo

    • just displays it here — periodically fetched, read-only on the anvil side
  • richer file editing: a real markdown editor with a live render preview (reuse render_markdown) before committing

  • webhooks (mind the SSRF item in docs/untrusted-mode.md)

  • attachment reclaim: an orphan sweep (delete attachments no committed file references) and/or a per-attachment delete action — the recourse once a repo hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy (tip-only vs any-ref), so it wants its own design pass

  • remove a repo's attachment + artifact dirs on repo delete — blocked: there is no repo-delete path yet (only the create-rollback uses it)

  • admin usage: per-repo drill-down, and a cheap cached/periodic variant if the on-demand disk walk gets slow on large instances

  • periodic disk usage cache: run usage::compute() on a timer (e.g., hourly) and store the result so the admin dashboard doesn't block on disk walks

  • repository preview images: extract the first "real" image (>few hundred px) from README.md on a periodic scan, cache the attachment hash, and display in repo listings for visual browsing

  • API tokens: a write scope (would need CSRF-exempt write paths) and last_used_at tracking

  • passkey follow-ups (docs/passkeys.md): conditional UI (autofill-style sign-in), and a warning before removing the last passkey on a password-less-by-preference account

  • secrets follow-ups (docs/secrets.md): authenticate anvild secret with an ssh signature instead of the account password; per-step rather than per- pipeline scoping; ssh-rsa recipients (needs an RSA-OAEP branch in both the Rust and the browser halves); drop a repo's secrets when repo delete lands