anvilsign in

collin/anvil

BoardRenderedSource

1# Todo
2
3## Add the ability to delete a repo
4
5Deleted no reboux should only be done through the settings.Menu of a repo must be the.Repo owner?And there should be some sort of confirmation dialogue that prevents it from being done on accident.Such as typing in the name of the repo.When you try to delete it
6
7## ability to link to deployed / live site
8
9## agent view, we have list of repos what about list of agents
10
11
12# Backlog
13
14
15- [ ] agent sessions, next milestones (docs/agent-sessions.md):
16 - a real checkout: the container clones from anvil's smart-HTTP endpoint and
17 pushes `agent/<id>` back. Needs a session-scoped push credential, which
18 does not exist (tokens are read-only, Bearer only on GET/HEAD)
19 - ref-scope that credential to `refs/heads/agent/*` — needs a ref filter in
20 receive-pack. Until it lands a session credential could write `main`
21 - trigger surfaces: a start button on a TODO item, an issue, a red CI run
22 - rate limiting, so automated pushes can't queue sessions endlessly once
23 triggers exist (`max_concurrent` bounds concurrency, not churn)
24 - a finished session's transcript rendered on its page (it is already on
25 disk under `sessions/<id>.log`; nothing reads it back yet)
26
27- [ ] pull requests (gix merge)
28- [ ] pull mirror (maybe): a repo that virtually mirrors a GitHub repo
29 - just displays it here — periodically fetched, read-only on the anvil side
30
31- [ ] richer file editing: a real markdown editor with a live render preview
32 (reuse `render_markdown`) before committing
33- [ ] webhooks (mind the SSRF item in `docs/untrusted-mode.md`)
34- [ ] attachment reclaim: an orphan sweep (delete attachments no committed file
35 references) and/or a per-attachment delete action — the recourse once a repo
36 hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy
37 (tip-only vs any-ref), so it wants its own design pass
38- [ ] remove a repo's attachment + artifact dirs on repo delete — blocked: there
39 is no repo-delete path yet (only the create-rollback uses it)
40- [ ] admin usage: per-repo drill-down, and a cheap cached/periodic variant if
41 the on-demand disk walk gets slow on large instances
42- [ ] periodic disk usage cache: run `usage::compute()` on a timer (e.g., hourly)
43 and store the result so the admin dashboard doesn't block on disk walks
44- [ ] repository preview images: extract the first "real" image (>few hundred px)
45 from README.md on a periodic scan, cache the attachment hash, and display in
46 repo listings for visual browsing
47- [ ] API tokens: a `write` scope (would need CSRF-exempt write paths) and
48 `last_used_at` tracking
49- [ ] single sign-on follow-ups (docs/oidc.md): silent renewal
50 (`prompt=none` on a short local session, which is what makes revoking an SSO
51 session propagate here), an admin view of who is linked to which `sub`, and
52 unlinking an account from the settings page
53- [ ] secrets follow-ups (docs/secrets.md): authenticate `anvild secret` with an
54 ssh signature instead of the account password; per-step rather than per-
55 pipeline scoping; `ssh-rsa` recipients (needs an RSA-OAEP branch in both the
56 Rust and the browser halves); drop a repo's secrets when repo delete lands