collin/anvil
Todo
ability to link to deployed / live site
agent view, we have list of repos what about list of agents
Backlog
-
agent sessions, next milestones (docs/agent-sessions.md):
- a real checkout: the container clones from anvil's smart-HTTP endpoint and
pushes
agent/<id>back. Needs a session-scoped push credential, which does not exist (tokens are read-only, Bearer only on GET/HEAD) - ref-scope that credential to
refs/heads/agent/*— needs a ref filter in receive-pack. Until it lands a session credential could writemain - trigger surfaces: a start button on a TODO item, an issue, a red CI run
- rate limiting, so automated pushes can't queue sessions endlessly once
triggers exist (
max_concurrentbounds concurrency, not churn) - a finished session's transcript rendered on its page (it is already on
disk under
sessions/<id>.log; nothing reads it back yet)
- a real checkout: the container clones from anvil's smart-HTTP endpoint and
pushes
-
pull requests (gix merge)
-
pull mirror (maybe): a repo that virtually mirrors a GitHub repo
- just displays it here — periodically fetched, read-only on the anvil side
-
richer file editing: a real markdown editor with a live render preview (reuse
render_markdown) before committing -
webhooks (mind the SSRF item in
docs/untrusted-mode.md) -
attachment reclaim: an orphan sweep (delete attachments no committed file references) and/or a per-attachment delete action — the recourse once a repo hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy (tip-only vs any-ref), so it wants its own design pass
-
admin usage: per-repo drill-down, and a cheap cached/periodic variant if the on-demand disk walk gets slow on large instances
-
periodic disk usage cache: run
usage::compute()on a timer (e.g., hourly) and store the result so the admin dashboard doesn't block on disk walks -
repository preview images: extract the first "real" image (>few hundred px) from README.md on a periodic scan, cache the attachment hash, and display in repo listings for visual browsing
-
API tokens: a
writescope (would need CSRF-exempt write paths) andlast_used_attracking -
single sign-on follow-ups (docs/oidc.md): silent renewal (
prompt=noneon a short local session, which is what makes revoking an SSO session propagate here), an admin view of who is linked to whichsub, and unlinking an account from the settings page -
secrets follow-ups (docs/secrets.md): authenticate
anvild secretwith an ssh signature instead of the account password; per-step rather than per- pipeline scoping;ssh-rsarecipients (needs an RSA-OAEP branch in both the Rust and the browser halves)