CodeIssuesDiscussionsWikiPull RequestsProjectsCommitsActionsReleasesContributorsPulse● GatesSecuritySettingsDeploymentsPipelineInsightsAgents✨ Explain✨ Ask AI✨ Workspace✨ Spec✨ Tests▓ Debt Map✨ NL Search🏛 Archaeology
Blame · Line-by-line history
TODO.md
Each line is annotated with the commit that last touched it. Click any SHA to jump to that commit and see the surrounding change.
| 58267aa | 1 | # Gluecron Master To-Do List |
| 2 | ||
| 43461a9 | 3 | Last updated: 2026-06-06 (rev 4 — full codebase audit complete, Bible is 35% of reality) |
| 58267aa | 4 | |
| 43461a9 | 5 | **IMPORTANT:** The BUILD_BIBLE.md documents ~35% of the actual codebase. 34 migrations (0043–0076) and 87+ lib files exist beyond what the Bible tracks. This list is based on direct code scanning, not the Bible. |
| 58267aa | 6 | |
| 43461a9 | 7 | Tick off items as they ship. Add `[x] YYYY-MM-DD commit:abc` when done. |
| 8 | Work top-to-bottom within each priority. | |
| 58267aa | 9 | |
| 10 | --- | |
| 11 | ||
| 43461a9 | 12 | ## 🔴 PRIORITY 1 — Configuration Blockers (Built, Just Not Configured) |
| 58267aa | 13 | |
| 43461a9 | 14 | These are NOT build tasks — the code is complete. They need ops/config action. |
| 58267aa | 15 | |
| 43461a9 | 16 | - [ ] **Set STRIPE_SECRET_KEY + STRIPE_WEBHOOK_SECRET in production** — Stripe Checkout, customer portal, and webhook handler are 100% built (`src/lib/stripe.ts`, `src/routes/billing.tsx`, `src/routes/stripe-webhook.ts`). The billing UI even shows a warning when the key is missing. Run `scripts/stripe-bootstrap.ts` to create products/prices in Stripe with the right lookup keys (`gluecron_pro_monthly` etc), then set the secrets on Fly.io. Zero code changes needed. |
| 17 | - [ ] **Verify SSH git push works end-to-end** — `src/lib/ssh-server.ts` is a full 545-line production implementation that starts at boot (`src/index.ts`). It handles `git-upload-pack` and `git-receive-pack`, does public-key auth against the `ssh_keys` table, and triggers post-receive hooks. Test from a clean machine: add an SSH key at `/settings`, then `git clone git@gluecron.com:user/repo.git`. If the SSH_PORT env var isn't set, default is 2222 — verify the port is open on the server. | |
| 18 | - [ ] **Enable AI Trio Review** — Three-model parallel PR review (security / correctness / style) is fully built in `src/lib/ai-review-trio.ts` and wired into `src/lib/ai-review.ts`. Set `AI_TRIO_REVIEW_ENABLED=1` to activate. This is a genuine differentiator — no other platform has this. | |
| 19 | - [ ] **Fix duplicate migration number 0065** — Two migration files both named `0065_*.sql`: one for `ai_cost_events` + `ai_budgets`, one for `auto_generate_tests`. Drizzle will apply one and ignore the other. Rename the auto-tests one to `0065b_auto_generate_tests.sql` or the next available number. | |
| 20 | - [ ] **Set SERVER_TARGETS_KEY** — Server targets encrypt SSH private keys via AES. If `SERVER_TARGETS_KEY` env var isn't set, deploy target creation will fail silently. Set a 32-byte hex key in production. | |
| 21 | - [ ] **Set PREVIEW_DOMAIN** — Branch preview URLs are computed as `${branchSlug}-${repoSlug}.preview.gluecron.com` or `PREVIEW_DOMAIN` env var. Set this to match where previews will actually be served. | |
| d3a4be7 | 22 | |
| 23 | --- | |
| 58267aa | 24 | |
| 43461a9 | 25 | ## 🟠 PRIORITY 2 — Genuine Code Gaps (Need Building) |
| 58267aa | 26 | |
| 43461a9 | 27 | These are confirmed missing by direct code inspection. |
| 58267aa | 28 | |
| 43461a9 | 29 | - [ ] **Container registry (Docker/OCI)** — No files exist for this anywhere in the codebase. npm package registry is complete (`src/lib/packages.ts`). The OCI push/pull protocol needs implementing: `GET /v2/`, `HEAD /v2/:name/blobs/:digest`, `POST /v2/:name/blobs/uploads/`, `PUT /v2/:name/manifests/:ref`. Without Docker support, teams with containerised apps can't fully leave GitHub. |
| 30 | - [ ] **Redis SSE fan-out** — `src/lib/sse.ts` is a single-process in-memory broadcaster. The TODO(scale) is right in the code. Multi-instance deploys mean live comment updates, PR live view, and push watch only reach subscribers on the same process. Replace the internal broadcaster with Redis pub/sub behind the same interface. | |
| 31 | - [ ] **Workflow cache SAVE** — `src/lib/actions/cache-action.ts` has an explicit TODO(v2) for the SAVE half. Only LOAD is implemented. Every CI run after the first runs cold. Wire save-on-job-success. | |
| 32 | - [ ] **Pack-content ruleset enforcement** — `commit_message_pattern`, `blocked_file_paths`, `max_file_size` in `src/lib/rulesets.ts` need actual git pack inspection to enforce at push time. Currently those rule types are advisory only. Implement in `src/lib/push-policy.ts`. | |
| 33 | - [ ] **Branch preview expiry cleanup** — `src/lib/branch-previews.ts` exports `expireOldPreviews()` but it's never called anywhere (not wired into autopilot). Branch preview rows have a 24h TTL in the DB schema (`expires_at`) but nothing enforces it. Add as an autopilot task. | |
| 34 | - [ ] **Server targets → customer-facing** — `src/routes/admin-server-targets.tsx` and migration `0073_server_targets.sql` exist but the routes are under `/admin/servers` — site-admin only. Build a customer-facing `/settings/deploy-targets` that lets any user add SSH deploy targets for their own repos. This is the push-to-your-own-server story. | |
| 35 | - [ ] **Claude Web Sessions → customer-facing** — Migration `0074_claude_web_sessions.sql` exists with `claude_web_sessions` + `claude_web_messages` tables. Admin-only in v1 per migration notes. Build the customer UI at `/:owner/:repo/claude` — browser-based Claude Code sessions with persistent transcript. This is a massive differentiator. | |
| 36 | - [ ] **AI budget hard enforcement** — `src/routes/billing-usage.tsx` confirms: the budget cap is advisory only ("Advisory cap; we warn when projected EOM exceeds it"). When a user's projected AI spend exceeds their cap, features should degrade gracefully. Wire `checkQuota()` from `src/lib/billing.ts` as a hard gate before AI feature calls. | |
| 37 | - [ ] **Spec-to-Live real-time progress UI** — Spec→PR exists. The remaining loop is PR→AI review→auto-merge→deploy→notification. More importantly, the user submits a spec and sees a blank page or redirect. Wire a live progress view (SSE-backed) showing each stage as it happens: "Writing code... Opening PR... AI reviewing... Gates passing... Merged in 1m 52s." This is the "wow" moment. | |
| 38 | - [ ] **Agent marketplace — real listings** — Migration `0070_agent_marketplace.sql` is complete with full schema (listings, installs, reviews, 30% revenue cut built in). The route `src/routes/marketplace-agents.tsx` exists. But there are only seed listings. Write a "Publish an agent" guide, reach out to 10 developers, get 20+ real listings. | |
| 58267aa | 39 | |
| 40 | --- | |
| 41 | ||
| 43461a9 | 42 | ## 🟡 PRIORITY 3 — Messaging (Every Page Needs This) |
| be18eee | 43 | |
| 43461a9 | 44 | - [ ] **Landing hero** (`src/views/landing.tsx`) — Kill "wake up to a merged PR." New headline: "Write the spec. Gluecron ships it." Subhead leads with numbers: "Spec to PR in 90 seconds. Push to live in 25. AI review, auto-merge, deploy — all automatic." |
| 45 | - [ ] **Landing "what's happening now" rail** — Replace async copy with real-time events: "PR #47 auto-merged 8 seconds ago", "AI flagged a secret in last push", "Spec shipped to draft PR in 1m 43s". Live-feeling, instant. | |
| 46 | - [ ] **vs-github AI rows** (`src/routes/vs-github.tsx`) — Reframe 10 AI-native comparison rows around latency not just capability. Add real timing numbers. GitHub Copilot waits for you to type; Gluecron acts the moment you open a PR. | |
| 47 | - [ ] **Demo page** (`src/routes/demo.tsx`) — Replace "watch autopilot work" with a live ticker of things happening right now. Stock-ticker feel, not a status report. | |
| 48 | - [ ] **Sleep Mode demoted** (`src/routes/sleep-mode.tsx`) — Move to secondary feature only. Never headline. Primary pitch everywhere = instant results. | |
| 49 | - [ ] **OG/meta descriptions** — Audit every page's `<meta description>` and OG tags. Strip "wake up to" and replace with speed language. | |
| 50 | - [ ] **Pricing page** (`src/routes/pricing.tsx`) — CTAs currently link to `/settings/billing?plan=X` not directly to checkout. Fine functionally but lead copy needs to hit the speed angle. Add the "spec to PR in 90 seconds" stat to the hero. | |
| 58267aa | 51 | |
| 52 | --- | |
| 53 | ||
| 43461a9 | 54 | ## 🔵 PRIORITY 4 — Polish & Customer Experience |
| 58267aa | 55 | |
| 43461a9 | 56 | ### Onboarding |
| 57 | - [ ] **Empty state for new repos** — Push your first commit / Import from GitHub / Try Spec-to-PR. Not a blank page. | |
| 58 | - [ ] **Onboarding email sequence** — T+0 welcome, T+1 day "try spec-to-PR", T+3 days "here's what AI did for similar repos". Resend sequences. | |
| 59 | - [ ] **Dashboard "AI just did this" widget** — What autopilot did in the last hour (not 7 days). PRs auto-merged, specs shipped, CI healed, secrets repaired. Real-time feel. | |
| 60 | - [ ] **Push Watch → make it discoverable** — The page (`/:owner/:repo/push/:sha`) exists and is polished. Add a "Live" pulsing link on the repo header that activates after every push. This is the first "wow" moment new users need to see. | |
| 61 | - [ ] **Repo overview AI stats strip** — Below the file tree: "AI merged 3 PRs this week · Saved ~4.5 hrs · 0 open security alerts." Makes AI value visible at a glance. | |
| 58267aa | 62 | |
| 43461a9 | 63 | ### Admin |
| 64 | - [ ] **Admin > AI cost breakdown** — Total AI spend this month, per feature (review/triage/CI healer/spec-to-PR/chat), top spenders. `aiCostEvents` table has everything needed. Unit economics. | |
| 65 | - [ ] **Admin > Stripe sync** — Stripe subscription status per user vs local plan. Flag mismatches. Link to Stripe dashboard. | |
| 66 | - [ ] **Admin > Autopilot health** — Last tick time, per-task success/error counts, average tick duration. Expose the CI healer, proactive monitor, stale sweep, and preview expiry tasks alongside existing tasks. | |
| 67 | - [ ] **Admin > User growth chart** — Signups over time, activation rate (created a repo), conversion rate (free→paid). | |
| 68 | - [ ] **K3 tasks on `/admin/autopilot`** — `auto-merge-sweep` and `ai-build-from-issues` run every tick but aren't listed in the admin UI. Add them with stats. | |
| d3a4be7 | 69 | |
| 43461a9 | 70 | ### Developer Experience |
| 71 | - [ ] **System/autopilot user** — K3 posts marker comments credited to the PR/issue author. Create `gluecron[bot]` synthetic user row. Autopilot actions should show a bot avatar. | |
| 72 | - [ ] **Notification preferences** — Flat checkbox list currently. Restructure into categories: AI activity, CI/CD, code review, mentions. Per-category toggle. | |
| 73 | - [ ] **Repo health badge on repo overview** — `computeHealthScore` exists, health page exists. Add a small badge to `RepoHeader`. | |
| 74 | - [ ] **AI Trio Review UI indicator** — When trio review is enabled, show three separate verdict pills on the PR (Security ✓, Correctness ✓, Style ✓) not one combined comment. The data is already structured that way. | |
| 75 | - [ ] **L1 sleep-mode column split** — `sleep_mode_digest` and weekly digest share `last_digest_sent_at`. Add `last_sleep_digest_sent_at` column. | |
| 76 | - [ ] **GitHub unlink route** — `/settings/sso/unlink` removes any SSO link. Add dedicated `/settings/github/unlink`. | |
| 77 | - [ ] **Branch preview expiry UX** — previews.tsx shows status pills (building/ready/failed/expired). Once expiry cleanup is wired, test the "expired" state renders correctly. | |
| 78 | ||
| 79 | ### Documentation & Help | |
| 80 | - [ ] **Docs site** — `/help` exists as a migration cheatsheet. Need: Getting Started, API reference, MCP server setup, Workflow YAML syntax, Agent publishing guide. Could be `/docs` served from the self-hosted repo. | |
| 81 | - [ ] **Changelog page** — `/changelog` with recent releases + AI-generated notes. Users have no way to know what shipped. | |
| 82 | - [ ] **Legal pages attorney review** — All four legal pages (`terms`, `privacy`, `dmca`, `acceptable-use`) are substantive drafts marked "DRAFT — requires attorney review." Get legal sign-off before any paid launch. | |
| 83 | - [ ] **Status page — polish** — `/status` and `/status.svg` exist. Add incident history, subscribe-to-alerts, make it look production-grade. | |
| 58267aa | 84 | |
| 85 | --- | |
| 86 | ||
| 43461a9 | 87 | ## 🟣 PRIORITY 5 — Growth & Distribution |
| d3a4be7 | 88 | |
| 43461a9 | 89 | - [ ] **60-second demo video** — Screen record: type a spec → AI writes code → PR opens → trio review posts → gates pass → auto-merged. Show elapsed time counter. No voiceover. Embed everywhere. |
| 90 | - [ ] **VS Code extension → publish** — `vscode-extension/` is built. Run `vsce package`, publish to VS Code Marketplace. Free discovery. | |
| 91 | - [ ] **CLI → publish to npm** — `cli/gluecron.ts` is built. Publish as `gluecron` npm package. `npx gluecron login` as zero-install entry. | |
| 92 | - [ ] **CLI → Homebrew formula** — `brew install gluecron`. Mac developer standard. | |
| 93 | - [ ] **JetBrains plugin** — Same four commands as VS Code. Kotlin plugin. Covers IntelliJ, WebStorm, GoLand. | |
| 94 | - [ ] **GitHub migration as primary CTA** — Bulk import is built (`src/routes/import-bulk.tsx`). Make "Migrate your GitHub org in 60 seconds" the hero CTA for GitHub users, not buried in the nav. | |
| 95 | - [ ] **Developer program page** — `/developer-program`: publish an agent, revenue share (30% platform cut is already in the schema), `gluecron-partner` badge, docs. | |
| 96 | - [ ] **Shareable AI hours saved card** — OG-image endpoint for Twitter/LinkedIn: "I saved 14 hours this week with Gluecron". Viral growth lever. | |
| 97 | - [ ] **Blog / devlog** — Monthly shipping updates. Developers follow platforms that ship visibly. | |
| d3a4be7 | 98 | |
| 43461a9 | 99 | --- |
| d3a4be7 | 100 | |
| 43461a9 | 101 | ## ⚫ PRIORITY 6 — Strategic / Long-Term |
| 102 | ||
| 103 | - [ ] **SOC 2 Type II** — Engage auditor, scope controls. 6–9 months. No enterprise deals without it. | |
| 104 | - [ ] **EU data residency** — Neon postgres EU region + Fly.io EU region. "Data region" selector at org creation. | |
| 105 | - [ ] **GDPR account deletion verification** — Migration `0049_account_deletion.sql` adds `deleted_at` and `deletion_scheduled_for`. Verify the full cascade is implemented: bare git repo deletion, related rows purged, audit log anonymised. | |
| 106 | - [ ] **Audit log SIEM export** — `GET /api/v2/audit?since=&format=json`. Required by enterprise security teams (Splunk, Datadog, Elastic). | |
| 107 | - [ ] **Enterprise sales page** — `/enterprise`: custom pricing, SSO, dedicated support SLA, data residency. Contact form → Calendly. | |
| 108 | - [ ] **Native iOS app** — Minimum viable: repo browser, notifications, PR approve/reject, AI chat. React Native. | |
| 109 | - [ ] **Native Android app** — Share React Native codebase with iOS. | |
| 110 | - [ ] **Multi-agent pipeline UI** — `agent-multiplayer.ts` and `agent_sessions`/`agent_leases` tables are complete. Wire a UI to define pipelines: Agent A writes, Agent B reviews, Agent C deploys. | |
| 111 | - [ ] **AI pair programmer (browser)** — Claude Code session embedded in a browser tab alongside the file editor. `claude_web_sessions` schema is ready (migration 0074), `src/routes/claude-web.tsx` exists — make it customer-facing. | |
| 112 | - [ ] **End-to-end test suite** — Playwright covering register → push → PR → AI review → merge. Catches flow regressions that unit tests miss. | |
| 113 | - [ ] **Load testing** — k6 or Artillery before any growth push. What happens at 1000 concurrent git pushes? | |
| 114 | - [ ] **Database connection pooling verification** — Confirm PgBouncer or Neon pooling is correctly configured for multi-instance load. | |
| d3a4be7 | 115 | |
| 43461a9 | 116 | --- |
| d3a4be7 | 117 | |
| 43461a9 | 118 | ## ✅ CONFIRMED COMPLETE (Direct Code Verification) |
| 119 | ||
| 120 | Verified by reading actual files — not just the Bible. | |
| 121 | ||
| 122 | **Revenue/Billing:** | |
| 123 | - Stripe Checkout + webhook + customer portal — complete, needs env vars only | |
| 124 | - Billing plans, quotas, usage tracking — complete | |
| 125 | - Billing UI with usage bars, plan cards, upgrade flow — complete | |
| 126 | - AI cost events + per-call tracking (`ai_cost_events` table) — complete | |
| 127 | - Budget cap warning system — complete (advisory; hard enforcement is a gap above) | |
| 128 | ||
| 129 | **Auth & Identity:** | |
| 130 | - SSH git push — complete (ssh-server.ts, 545 lines, wired at boot) | |
| 131 | - Password reset, email verification, magic link sign-in — complete | |
| 132 | - Google OAuth — complete | |
| 133 | - Playground anonymous accounts — complete | |
| 134 | - Account deletion with grace period — complete | |
| 135 | - Terms acceptance audit trail — complete | |
| 136 | ||
| 137 | **AI Features (all wired, not stubs):** | |
| 138 | - AI CI healer (auto-fixes failed workflow runs) — complete, runs every 5 min | |
| 139 | - AI proactive monitor (platform health surveillance) — complete, runs hourly | |
| 140 | - Stale PR/issue sweep (two-stage poke + auto-close) — complete, runs every 5 min | |
| 141 | - AI trio review (three-model parallel: security/correctness/style) — complete, opt-in | |
| 142 | - AI standup generation (daily/weekly briefs) — complete | |
| 143 | - Repair flywheel (learning cache for patches) — complete | |
| 144 | - Voice-to-PR — complete (1092 lines) | |
| 145 | - Multi-repo refactoring — complete | |
| 146 | - Migration assistant (AI-driven major dep upgrades) — complete | |
| 147 | ||
| 148 | **Developer Experience:** | |
| 149 | - Per-repo AI chat — complete (repo-chat.tsx, 967 lines) | |
| 150 | - Personal cross-repo AI chat — complete (personal-chat.tsx, 1137 lines) | |
| 151 | - Hosted Claude loops (deploy Claude agents as endpoints) — complete | |
| 152 | - Cloud dev environments (browser IDE) — complete (schema + routes, feature-flagged) | |
| 153 | - Branch preview URLs — complete (URL gen; expiry cleanup missing — see Priority 2) | |
| 154 | - PR sandboxes — complete (4h TTL, auto-provision on PR open) | |
| 155 | - PR live co-editing with cursor presence — complete | |
| 156 | - Comment moderation queue — complete | |
| 157 | - Import secrets from GitHub — complete | |
| 158 | - Agent multiplayer (sessions, leases, budgets) — complete | |
| 159 | ||
| 160 | **Integrations:** | |
| 161 | - Slack/Discord/Teams chat notifications — complete | |
| 162 | - Durable webhook delivery with exponential backoff retry — complete | |
| 163 | - Synthetic uptime monitoring — complete | |
| 164 | - Deploy timeline + step streaming — complete | |
| 165 | ||
| 166 | **Admin:** | |
| 167 | - /admin/diagnose — 14 system health checks — complete | |
| 168 | - /admin/self-host — self-hosting wizard — complete | |
| 169 | - /admin/servers — SSH deploy targets — complete (admin-only; customer rollout is a gap) | |
| 170 | ||
| 171 | **Everything in BUILD_BIBLE §2 marked ✅** is confirmed present in the codebase. The Bible claims 100% accuracy for what it documents — no phantom features found. | |
| 58267aa | 172 | |
| 173 | --- | |
| 174 | ||
| 43461a9 | 175 | ## Notes |
| 58267aa | 176 | |
| 43461a9 | 177 | - `- [ ]` = not started / not configured |
| 178 | - `- [x] YYYY-MM-DD commit:abc` = done | |
| 179 | - Bible is accurate but covers only ~35% of the codebase by file count | |
| 180 | - 34 migrations beyond 0042 represent major post-Bible development | |
| 181 | - When in doubt: scan the code, don't trust the Bible |