diff --git a/api/pve_action.php b/api/pve_action.php index fd73095..d10df22 100644 --- a/api/pve_action.php +++ b/api/pve_action.php @@ -1,4 +1,19 @@ false, 'error' => 'Unauthorized']); + exit; +} +if (($_SESSION['role'] ?? 'user') !== 'admin') { + http_response_code(403); + header('Content-Type: application/json; charset=utf-8'); + echo json_encode(['ok' => false, 'error' => 'Forbidden']); + exit; +} + require_once __DIR__ . '/../lib/PveApi.php'; $cfg = require __DIR__ . '/../config/pve.php'; $pve = new PveApi($cfg); @@ -6,22 +21,21 @@ $pve = new PveApi($cfg); header('Content-Type: application/json; charset=utf-8'); try { - if ($_SERVER['REQUEST_METHOD'] !== 'POST') { - http_response_code(405); - echo json_encode(['ok' => false, 'error' => 'Method not allowed']); - exit; - } + if ($_SERVER['REQUEST_METHOD'] !== 'POST') { + http_response_code(405); + echo json_encode(['ok' => false, 'error' => 'Method not allowed']); + exit; + } - $vmid = (int)($_POST['vmid'] ?? 0); - $action = (string)($_POST['action'] ?? ''); + $vmid = (int)($_POST['vmid'] ?? 0); + $action = (string)($_POST['action'] ?? ''); - // optional: hier deine Dashboard-Auth checken! - if ($vmid <= 0) throw new InvalidArgumentException("vmid fehlt/ungültig"); + if ($vmid <= 0) throw new InvalidArgumentException("vmid fehlt/ungültig"); - $upid = $pve->powerAction($vmid, $action); - echo json_encode(['ok' => true, 'vmid' => $vmid, 'action' => $action, 'upid' => $upid]); + $upid = $pve->powerAction($vmid, $action); + echo json_encode(['ok' => true, 'vmid' => $vmid, 'action' => $action, 'upid' => $upid]); } catch (Throwable $e) { - http_response_code(400); - echo json_encode(['ok' => false, 'error' => $e->getMessage()]); + http_response_code(400); + echo json_encode(['ok' => false, 'error' => $e->getMessage()]); } diff --git a/api/pve_list.php b/api/pve_list.php index 6af67d0..e9e1030 100644 --- a/api/pve_list.php +++ b/api/pve_list.php @@ -1,4 +1,18 @@ false, 'error' => 'Unauthorized']); + exit; +} +if (($_SESSION['role'] ?? 'user') !== 'admin') { + http_response_code(403); + header('Content-Type: application/json; charset=utf-8'); + echo json_encode(['ok' => false, 'error' => 'Forbidden']); + exit; +} require_once __DIR__ . '/../lib/PveApi.php'; $cfg = require __DIR__ . '/../config/pve.php'; @@ -7,49 +21,48 @@ $pve = new PveApi($cfg); header('Content-Type: application/json; charset=utf-8'); try { - $lxcs = $pve->listLxc(); // array mit vmid, name, status, cpu, mem, etc. - $vms = $pve->listQemu(); // array mit vmid, name, status, cpu, mem, etc. + $lxcs = $pve->listLxc(); + $vms = $pve->listQemu(); - $all = []; + $all = []; - foreach ($lxcs as $c) { - $vmid = (int)($c['vmid'] ?? 0); - if ($vmid >= 100 && $vmid <= 199) { - $all[] = [ - 'vmid' => $vmid, - 'type' => 'lxc', - 'name' => (string)($c['name'] ?? "LXC {$vmid}"), - 'status' => (string)($c['status'] ?? 'unknown'), - 'uptime' => (int)($c['uptime'] ?? 0), - 'cpu' => (float)($c['cpu'] ?? 0), - 'mem' => (int)($c['mem'] ?? 0), - 'maxmem' => (int)($c['maxmem'] ?? 0), - ]; + foreach ($lxcs as $c) { + $vmid = (int)($c['vmid'] ?? 0); + if ($vmid >= 100 && $vmid <= 199) { + $all[] = [ + 'vmid' => $vmid, + 'type' => 'lxc', + 'name' => (string)($c['name'] ?? "LXC {$vmid}"), + 'status' => (string)($c['status'] ?? 'unknown'), + 'uptime' => (int)($c['uptime'] ?? 0), + 'cpu' => (float)($c['cpu'] ?? 0), + 'mem' => (int)($c['mem'] ?? 0), + 'maxmem' => (int)($c['maxmem'] ?? 0), + ]; + } } - } - foreach ($vms as $v) { - $vmid = (int)($v['vmid'] ?? 0); - if ($vmid >= 200 && $vmid <= 299) { - $all[] = [ - 'vmid' => $vmid, - 'type' => 'qemu', - 'name' => (string)($v['name'] ?? "VM {$vmid}"), - 'status' => (string)($v['status'] ?? 'unknown'), - 'uptime' => (int)($v['uptime'] ?? 0), - 'cpu' => (float)($v['cpu'] ?? 0), - 'mem' => (int)($v['mem'] ?? 0), - 'maxmem' => (int)($v['maxmem'] ?? 0), - ]; + foreach ($vms as $v) { + $vmid = (int)($v['vmid'] ?? 0); + if ($vmid >= 200 && $vmid <= 299) { + $all[] = [ + 'vmid' => $vmid, + 'type' => 'qemu', + 'name' => (string)($v['name'] ?? "VM {$vmid}"), + 'status' => (string)($v['status'] ?? 'unknown'), + 'uptime' => (int)($v['uptime'] ?? 0), + 'cpu' => (float)($v['cpu'] ?? 0), + 'mem' => (int)($v['mem'] ?? 0), + 'maxmem' => (int)($v['maxmem'] ?? 0), + ]; + } } - } - // Sort: erst LXCs, dann VMs oder nach vmid - usort($all, fn($a, $b) => $a['vmid'] <=> $b['vmid']); + usort($all, fn($a, $b) => $a['vmid'] <=> $b['vmid']); - echo json_encode(['ok' => true, 'items' => $all], JSON_UNESCAPED_UNICODE); + echo json_encode(['ok' => true, 'items' => $all], JSON_UNESCAPED_UNICODE); } catch (Throwable $e) { - http_response_code(400); - echo json_encode(['ok' => false, 'error' => $e->getMessage()]); + http_response_code(400); + echo json_encode(['ok' => false, 'error' => $e->getMessage()]); }