Bezbednost: ispravke kontrole pristupa u admin i handler sloju

This commit is contained in:
2026-06-05 22:41:20 +02:00
parent ccc08aee08
commit 2b3636528f
44 changed files with 1310 additions and 480 deletions
+11 -38
View File
@@ -4,14 +4,7 @@
{{define "dodatni-css"}}
<style>
@keyframes slideDown {
from { opacity: 0; transform: translateY(-10px); }
to { opacity: 1; transform: translateY(0); }
}
.poruka-animacija {
animation: slideDown 0.3s ease forwards;
}
.poruka-animacija { animation: slideDown 0.3s ease forwards; }
.pod-tabela tbody tr:nth-child(1) { animation-delay: 0.04s; }
.pod-tabela tbody tr:nth-child(2) { animation-delay: 0.08s; }
@@ -59,11 +52,7 @@
<!-- gornja traka -->
<div style="display:flex;gap:10px;flex-wrap:wrap;align-items:center;">
<a href="/podsetnici/novi"
style="padding:8px 16px;background:var(--sb-akcent);color:#fff;border-radius:8px;font-size:14px;font-weight:500;text-decoration:none;white-space:nowrap;transition:opacity 0.2s;"
onmouseover="this.style.opacity='0.85'" onmouseout="this.style.opacity='1'">
+ Novi podsetnik
</a>
<a href="/podsetnici/novi" class="btn-primarno">+ Novi podsetnik</a>
<form method="GET" action="/podsetnici" style="display:flex;gap:8px;align-items:center;flex:1;min-width:200px;flex-wrap:wrap;">
<label style="display:flex;align-items:center;gap:6px;font-size:14px;color:var(--tekst-sporedni);cursor:pointer;white-space:nowrap;">
<input type="checkbox" name="samo_aktivni" value="1" {{if .SamoAktivni}}checked{{end}}
@@ -88,10 +77,7 @@
</thead>
<tbody>
{{range .Podsetnici}}
<tr class="animiraj {{if .JePrekoracen}}red-prekoracen{{end}}"
style="border-bottom:0.5px solid var(--ivica);transition:background 0.15s;"
onmouseover="this.style.background='var(--pozadina)'"
onmouseout="this.style.background=''">
<tr class="animiraj red-tabele {{if .JePrekoracen}}red-prekoracen{{end}}">
<td style="padding:12px 16px;">
<div style="font-size:14px;font-weight:500;color:var(--tekst-glavni);">{{.Naslov}}</div>
{{if .Napomena}}
@@ -112,23 +98,15 @@
</td>
<td style="padding:12px 16px;text-align:center;">
<div style="display:flex;align-items:center;justify-content:center;gap:8px;">
<a href="/podsetnici/izmeni/{{.ID}}"
style="padding:4px 10px;background:var(--sb-aktivan);color:var(--tekst-jak);border-radius:6px;font-size:12px;text-decoration:none;transition:opacity 0.2s;"
onmouseover="this.style.opacity='0.8'" onmouseout="this.style.opacity='1'">
Izmeni
</a>
<a href="/podsetnici/izmeni/{{.ID}}" class="btn-primarno-malo">Izmeni</a>
<form method="POST" action="/podsetnici/zavrseno/{{.ID}}" style="display:inline;">
<button type="submit"
style="padding:4px 10px;background:var(--sb-aktivan);color:var(--tekst-jak);border:none;border-radius:6px;font-size:12px;cursor:pointer;transition:opacity 0.2s;"
onmouseover="this.style.opacity='0.8'" onmouseout="this.style.opacity='1'">
<button type="submit" class="btn-primarno-malo">
{{if .Zavrseno}}Aktiviraj{{else}}Završi{{end}}
</button>
</form>
<form method="POST" action="/podsetnici/obrisi/{{.ID}}" style="display:inline;">
<button type="submit"
onclick="return confirm('Da li ste sigurni da želite da obrišete podsetnik?')"
style="padding:4px 10px;background:#dc2626;color:#fff;border:none;border-radius:6px;font-size:12px;cursor:pointer;transition:opacity 0.2s;"
onmouseover="this.style.opacity='0.8'" onmouseout="this.style.opacity='1'">
<button type="submit" class="btn-obrisi-malo"
data-potvrda="Da li ste sigurni da želite da obrišete podsetnik?">
Obriši
</button>
</form>
@@ -172,20 +150,15 @@
{{.DatumPodsecanja.Format "02.01.2006."}}
</div>
<div style="display:flex;gap:8px;flex-wrap:wrap;">
<a href="/podsetnici/izmeni/{{.ID}}"
style="padding:6px 14px;background:var(--sb-aktivan);color:var(--tekst-jak);border-radius:6px;font-size:13px;text-decoration:none;">
Izmeni
</a>
<a href="/podsetnici/izmeni/{{.ID}}" class="btn-primarno-malo">Izmeni</a>
<form method="POST" action="/podsetnici/zavrseno/{{.ID}}" style="display:inline;">
<button type="submit"
style="padding:6px 14px;background:var(--sb-aktivan);color:var(--tekst-jak);border:none;border-radius:6px;font-size:13px;cursor:pointer;">
<button type="submit" class="btn-primarno-malo">
{{if .Zavrseno}}Aktiviraj{{else}}Završi{{end}}
</button>
</form>
<form method="POST" action="/podsetnici/obrisi/{{.ID}}" style="display:inline;">
<button type="submit"
onclick="return confirm('Da li ste sigurni da želite da obrišete podsetnik?')"
style="padding:6px 14px;background:#dc2626;color:#fff;border:none;border-radius:6px;font-size:13px;cursor:pointer;">
<button type="submit" class="btn-obrisi-malo"
data-potvrda="Da li ste sigurni da želite da obrišete podsetnik?">
Obriši
</button>
</form>