anvilsign in

collin/anvil

BoardRenderedSource

1# Todo
2
3## Add the ability to delete a repo
4
5Deleted no reboux should only be done through the settings.Menu of a repo must be the.Repo owner?And there should be some sort of confirmation dialogue that prevents it from being done on accident.Such as typing in the name of the repo.When you try to delete it
6
7
8# Backlog
9
10
11- [ ] pull requests (gix merge)
12- [ ] pull mirror (maybe): a repo that virtually mirrors a GitHub repo
13 - just displays it here — periodically fetched, read-only on the anvil side
14
15- [ ] richer file editing: a real markdown editor with a live render preview
16 (reuse `render_markdown`) before committing
17- [ ] webhooks (mind the SSRF item in `docs/untrusted-mode.md`)
18- [ ] attachment reclaim: an orphan sweep (delete attachments no committed file
19 references) and/or a per-attachment delete action — the recourse once a repo
20 hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy
21 (tip-only vs any-ref), so it wants its own design pass
22- [ ] remove a repo's attachment + artifact dirs on repo delete — blocked: there
23 is no repo-delete path yet (only the create-rollback uses it)
24- [ ] admin usage: per-repo drill-down, and a cheap cached/periodic variant if
25 the on-demand disk walk gets slow on large instances
26- [ ] periodic disk usage cache: run `usage::compute()` on a timer (e.g., hourly)
27 and store the result so the admin dashboard doesn't block on disk walks
28- [ ] repository preview images: extract the first "real" image (>few hundred px)
29 from README.md on a periodic scan, cache the attachment hash, and display in
30 repo listings for visual browsing
31- [ ] API tokens: a `write` scope (would need CSRF-exempt write paths) and
32 `last_used_at` tracking
33- [ ] single sign-on follow-ups (docs/oidc.md): silent renewal
34 (`prompt=none` on a short local session, which is what makes revoking an SSO
35 session propagate here), an admin view of who is linked to which `sub`, and
36 unlinking an account from the settings page
37- [ ] secrets follow-ups (docs/secrets.md): authenticate `anvild secret` with an
38 ssh signature instead of the account password; per-step rather than per-
39 pipeline scoping; `ssh-rsa` recipients (needs an RSA-OAEP branch in both the
40 Rust and the browser halves); drop a repo's secrets when repo delete lands