anvilsign in

collin/anvil

BoardRenderedSource

Todo

Add the ability to delete a repo

Deleted no reboux should only be done through the settings.Menu of a repo must be the.Repo owner?And there should be some sort of confirmation dialogue that prevents it from being done on accident.Such as typing in the name of the repo.When you try to delete it

ability to link to deployed / live site

agent view, we have list of repos what about list of agents

Backlog

  • agent sessions, next milestones (docs/agent-sessions.md):

    • a real checkout: the container clones from anvil's smart-HTTP endpoint and pushes agent/<id> back. Needs a session-scoped push credential, which does not exist (tokens are read-only, Bearer only on GET/HEAD)
    • ref-scope that credential to refs/heads/agent/* — needs a ref filter in receive-pack. Until it lands a session credential could write main
    • trigger surfaces: a start button on a TODO item, an issue, a red CI run
    • rate limiting, so automated pushes can't queue sessions endlessly once triggers exist (max_concurrent bounds concurrency, not churn)
    • a finished session's transcript rendered on its page (it is already on disk under sessions/<id>.log; nothing reads it back yet)
  • pull requests (gix merge)

  • pull mirror (maybe): a repo that virtually mirrors a GitHub repo

    • just displays it here — periodically fetched, read-only on the anvil side
  • richer file editing: a real markdown editor with a live render preview (reuse render_markdown) before committing

  • webhooks (mind the SSRF item in docs/untrusted-mode.md)

  • attachment reclaim: an orphan sweep (delete attachments no committed file references) and/or a per-attachment delete action — the recourse once a repo hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy (tip-only vs any-ref), so it wants its own design pass

  • remove a repo's attachment + artifact dirs on repo delete — blocked: there is no repo-delete path yet (only the create-rollback uses it)

  • admin usage: per-repo drill-down, and a cheap cached/periodic variant if the on-demand disk walk gets slow on large instances

  • periodic disk usage cache: run usage::compute() on a timer (e.g., hourly) and store the result so the admin dashboard doesn't block on disk walks

  • repository preview images: extract the first "real" image (>few hundred px) from README.md on a periodic scan, cache the attachment hash, and display in repo listings for visual browsing

  • API tokens: a write scope (would need CSRF-exempt write paths) and last_used_at tracking

  • single sign-on follow-ups (docs/oidc.md): silent renewal (prompt=none on a short local session, which is what makes revoking an SSO session propagate here), an admin view of who is linked to which sub, and unlinking an account from the settings page

  • secrets follow-ups (docs/secrets.md): authenticate anvild secret with an ssh signature instead of the account password; per-step rather than per- pipeline scoping; ssh-rsa recipients (needs an RSA-OAEP branch in both the Rust and the browser halves); drop a repo's secrets when repo delete lands