collin/anvil
Todo2 open
- ability to link to deployed / live site
- agent view, we have list of repos what about list of agents
Backlog12 open
agent sessions, next milestones (docs/agent-sessions.md):
- a real checkout: the container clones from anvil's smart-HTTP endpoint and
pushes
agent/<id>back. Needs a session-scoped push credential, which does not exist (tokens are read-only, Bearer only on GET/HEAD) - ref-scope that credential to
refs/heads/agent/*— needs a ref filter in receive-pack. Until it lands a session credential could writemain - trigger surfaces: a start button on a TODO item, an issue, a red CI run
- rate limiting, so automated pushes can't queue sessions endlessly once
triggers exist (
max_concurrentbounds concurrency, not churn) - a finished session's transcript rendered on its page (it is already on
disk under
sessions/<id>.log; nothing reads it back yet)
- a real checkout: the container clones from anvil's smart-HTTP endpoint and
pushes
- pull requests (gix merge)
pull mirror (maybe): a repo that virtually mirrors a GitHub repo
- just displays it here — periodically fetched, read-only on the anvil side
richer file editing: a real markdown editor with a live render preview
(reuse
render_markdown) before committing- webhooks (mind the SSRF item in
docs/untrusted-mode.md) attachment reclaim: an orphan sweep (delete attachments no committed file
references) and/or a per-attachment delete action — the recourse once a repo hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy (tip-only vs any-ref), so it wants its own design pass
admin usage: per-repo drill-down, and a cheap cached/periodic variant if
the on-demand disk walk gets slow on large instances
periodic disk usage cache: run
usage::compute()on a timer (e.g., hourly)and store the result so the admin dashboard doesn't block on disk walks
repository preview images: extract the first "real" image (>few hundred px)
from README.md on a periodic scan, cache the attachment hash, and display in repo listings for visual browsing
API tokens: a
writescope (would need CSRF-exempt write paths) andlast_used_attrackingsingle sign-on follow-ups (docs/oidc.md): silent renewal
(
prompt=noneon a short local session, which is what makes revoking an SSO session propagate here), an admin view of who is linked to whichsub, and unlinking an account from the settings pagesecrets follow-ups (docs/secrets.md): authenticate
anvild secretwith anssh signature instead of the account password; per-step rather than per- pipeline scoping;
ssh-rsarecipients (needs an RSA-OAEP branch in both the Rust and the browser halves)