Roadmap

What's left, grouped by how soon it's coming: Next (queued up), Later (planned, not yet started). Finished work — phases 1 through 14, telemetry, hardening, streaming, /test, database-backed theme and prompt history, and frontend performance & polish — moved to CHANGELOG.md.

Next

Git over SSH in the Docker image

Git (status, commit, pull, push, sync) runs through the bridge in both local and remote mode, with GIT_TERMINAL_PROMPT=0 and ssh -o BatchMode=yes, so it uses whatever SSH setup the bridge's machine has. A natively run bridge already works with the host's ~/.ssh and ssh-agent; the bridge in the Docker image has no ssh client, agent, or SSH config. Make it work there without private keys ever entering the container:

Remaining manual verification

The model setup and code hardening follow-ups are implemented. Native and browser contracts cover both modes, failures, stale results and fallbacks. Docker checks cover authenticated WebSocket PTYs, real-model streaming, remote file writes, host-owned Git workspaces, supervisor shutdown and bridge-disabled SSE fallback. Reload recovery covers mid-run and multi-window checks, plus the user-confirmed restoration of an OS-picked local folder.

The following checks still require hands-on device or environment testing:

Full code editor: editing, structure and navigation

Build out the existing syntax-highlighted Edit view into a daily-use code editor. Keep numbered Inline/Split diffs, previews for supported formats (Markdown/images/PDF and plain-text documents), including Markdown gutters on changed blocks/items/rows and inline prose differences for Git HEAD and pending agent edits, Find, pending-edit review and agent editor context intact. Editing must work without a host language server in both modes.

The shared Rust document/transaction engine, grouped undo/redo, per-file/project history, indentation/EditorConfig controls, block-aware Enter and paired typing are in place. Line movement/duplication/deletion, snippet duplication, line/block comments, explicit indentation-matching paste, selected-line reindent, folding, reading/navigation and Find/Replace use the same engine. See editor controls. Continue with:

Rust/WebAssembly architecture: keep the editor in Rust/Leptos compiled to WASM; do not embed CodeMirror, Monaco or another substantial JavaScript editor client. Those editors are feature references only. Build reusable Rust document, selection, edit-transaction, undo/history, command and fold-range primitives, with one Leptos editor component. Evaluate WASM-compatible Rust crates for text storage and syntax parsing before choosing dependencies. Native/browser storage measurements compare the current document with Crop/Ropey edits, display materialization and UTF-16 indexing; retain current production storage until viewport/worker work changes its access pattern. Keep browser glue thin: DOM events, input/IME, selection, clipboard, measurements and worker transport; editing policy and algorithms belong in Rust. Preserve native browser input behavior where possible, and evaluate a richer view for multiple selections beyond the current projected textarea/paint surface.

Workspace reads/writes, settings and review policy stay in shared facades. Save user preferences in database settings, never localStorage. Verify touch/IME/accessibility, Unicode/caret mapping, incremental parsing, large-file responsiveness, theme integration and PWA loading. Benchmark viewport rendering and establish large-file fallbacks before claiming completion; run behavioral contracts in both modes.

Completion, diagnostics, hover, symbol navigation, rename, formatting and code actions belong to the following Code intelligence item, using the editor's extension points. Minimap, Vim/Emacs emulation and similar extras are optional later work.

Research references: VS Code editing, CodeMirror baseline, CodeMirror Tab accessibility, CodeMirror features, Monaco support/architecture, and EditorConfig.

Code intelligence: in-browser WASM linters & LSP

Run lightweight WebAssembly linters directly in the browser for instant diagnostics, with no language runtimes on the host, and optionally bridge to host language servers.

Build on the Full code editor component and its document/selection/extension APIs. Bring real-time code intelligence (syntax errors, lint squiggles, tooltips, autocomplete) into the editor while keeping the core diagnostics engine 100% shared between Remote and Local mode:

Process execution: MCP client & headless browser

The rest of the Phase 11 bridge work that isn't built yet — the bridge's PTY sessions, run_command tool, and terminal pane are done and in the changelog, but:

Later

Multi-user

Only needed once more than one account can exist (today registration closes after the first account):

Web Push (optional)

Sandboxed tool execution (optional)

The VFS already confines the file tools (read_file, write_file, list_dir, search) to the working directory, but run_command and the git tools spawn real host processes as the user, which the VFS doesn't cover. Approval modes now allow commands to run without asking. Offer an opt-in mode that runs the agent's tool executor in a container or as a restricted user with only the project folder mounted and optionally no network, while the user's own terminal keeps full access. Off by default; recommended alongside YOLO mode. Use the existing shared tool-execution trait.

Productionization & public release (1.0)

The milestone that marks 1.0 — the first version tagged for public use. A hygiene and packaging pass once the hardening sequence, refactors and the main Next features have landed — before sharing the repo publicly.

Offline & error-state recovery

Parking lot

Ideas without a phase yet:

Explicitly out of scope