anvilsign in

collin/anvil

BoardRenderedSource

1# Todo
2
3## Add the ability to delete a repo
4
5Deleted no reboux should only be done through the settings.Menu of a repo must be the.Repo owner?And there should be some sort of confirmation dialogue that prevents it from being done on accident.Such as typing in the name of the repo.When you try to delete it
6
7## ability to link to deployed / live site
8
9
10# Backlog
11
12
13- [ ] agent sessions, next milestones (docs/agent-sessions.md):
14 - a real checkout: the container clones from anvil's smart-HTTP endpoint and
15 pushes `agent/<id>` back. Needs a session-scoped push credential, which
16 does not exist (tokens are read-only, Bearer only on GET/HEAD)
17 - ref-scope that credential to `refs/heads/agent/*` — needs a ref filter in
18 receive-pack. Until it lands a session credential could write `main`
19 - trigger surfaces: a start button on a TODO item, an issue, a red CI run
20 - rate limiting, so automated pushes can't queue sessions endlessly once
21 triggers exist (`max_concurrent` bounds concurrency, not churn)
22 - a finished session's transcript rendered on its page (it is already on
23 disk under `sessions/<id>.log`; nothing reads it back yet)
24
25- [ ] pull requests (gix merge)
26- [ ] pull mirror (maybe): a repo that virtually mirrors a GitHub repo
27 - just displays it here — periodically fetched, read-only on the anvil side
28
29- [ ] richer file editing: a real markdown editor with a live render preview
30 (reuse `render_markdown`) before committing
31- [ ] webhooks (mind the SSRF item in `docs/untrusted-mode.md`)
32- [ ] attachment reclaim: an orphan sweep (delete attachments no committed file
33 references) and/or a per-attachment delete action — the recourse once a repo
34 hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy
35 (tip-only vs any-ref), so it wants its own design pass
36- [ ] remove a repo's attachment + artifact dirs on repo delete — blocked: there
37 is no repo-delete path yet (only the create-rollback uses it)
38- [ ] admin usage: per-repo drill-down, and a cheap cached/periodic variant if
39 the on-demand disk walk gets slow on large instances
40- [ ] periodic disk usage cache: run `usage::compute()` on a timer (e.g., hourly)
41 and store the result so the admin dashboard doesn't block on disk walks
42- [ ] repository preview images: extract the first "real" image (>few hundred px)
43 from README.md on a periodic scan, cache the attachment hash, and display in
44 repo listings for visual browsing
45- [ ] API tokens: a `write` scope (would need CSRF-exempt write paths) and
46 `last_used_at` tracking
47- [ ] single sign-on follow-ups (docs/oidc.md): silent renewal
48 (`prompt=none` on a short local session, which is what makes revoking an SSO
49 session propagate here), an admin view of who is linked to which `sub`, and
50 unlinking an account from the settings page
51- [ ] secrets follow-ups (docs/secrets.md): authenticate `anvild secret` with an
52 ssh signature instead of the account password; per-step rather than per-
53 pipeline scoping; `ssh-rsa` recipients (needs an RSA-OAEP branch in both the
54 Rust and the browser halves); drop a repo's secrets when repo delete lands