- Restructure /admin into a (dashboard) route group with a sidebar shell
(Galerija / Storitve / Novice / Kontakt / Uporabniki) and active-tab state
- Hide the public site header/footer on all /admin routes
- Centralize auth in hooks.server.ts so page loads, form actions AND endpoints
are all gated (layout load guards don't cover actions)
- Users section (admin-only): add user, change role, reset password, delete;
safeguards prevent self-delete and removing the last admin; server-side role
checks (editors get 403 even if UI hidden)
- Login redirects already-authed users; logout moved to /admin/logout endpoint
- Gallery management moved under /admin/gallery; shared .admin-* styles in app.css
- Fix flexbox overflow in the dashboard main column (min-width:0, box-sizing)
- Placeholder tabs for Services/News/Contact (Phases 3-5)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Migrate the gallery/admin off the static + Supabase setup to a self-hosted
full-stack app that runs on the home server behind nginx.
- Switch adapter-static -> adapter-node
- SQLite via Drizzle (users, sessions, gallery_images); migrations run on startup
- Server-side session auth (argon2 hashing, httpOnly cookie, SHA-256 stored token,
sliding expiry) wired through hooks.server.ts
- Admin: server-side login, route guard, gallery upload/delete via form actions
- Public gallery is now SSR from the DB; /uploads/[...path] serves images in dev
- scripts/create-admin.js + db:generate/db:migrate/create-admin npm scripts
- Remove @supabase/supabase-js and the client-side gallery/admin code
- Fix pre-existing imageOnRight boolean prop type in Main.svelte
- ADMIN_SETUP.md rewritten for local dev + home-server deploy (systemd, nginx, backups)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>