security: protect proxmox api endpoints with session authentication

- Added authentication checks to pve_action.php and pve_list.php
- Require valid logged-in session before API access
- Restrict Proxmox actions to admin users only
- Return HTTP 401 for unauthenticated requests
- Return HTTP 403 for unauthorized users
- Keep existing API logic unchanged
This commit is contained in:
2026-07-22 02:03:20 +02:00
parent d858e062f1
commit 882155a7b4
2 changed files with 76 additions and 49 deletions
+27 -13
View File
@@ -1,4 +1,19 @@
<?php
require_once __DIR__ . '/../config/session.php';
if (!isset($_SESSION['loggedin']) || $_SESSION['loggedin'] !== true) {
http_response_code(401);
header('Content-Type: application/json; charset=utf-8');
echo json_encode(['ok' => false, 'error' => 'Unauthorized']);
exit;
}
if (($_SESSION['role'] ?? 'user') !== 'admin') {
http_response_code(403);
header('Content-Type: application/json; charset=utf-8');
echo json_encode(['ok' => false, 'error' => 'Forbidden']);
exit;
}
require_once __DIR__ . '/../lib/PveApi.php';
$cfg = require __DIR__ . '/../config/pve.php';
$pve = new PveApi($cfg);
@@ -6,22 +21,21 @@ $pve = new PveApi($cfg);
header('Content-Type: application/json; charset=utf-8');
try {
if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
http_response_code(405);
echo json_encode(['ok' => false, 'error' => 'Method not allowed']);
exit;
}
if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
http_response_code(405);
echo json_encode(['ok' => false, 'error' => 'Method not allowed']);
exit;
}
$vmid = (int)($_POST['vmid'] ?? 0);
$action = (string)($_POST['action'] ?? '');
$vmid = (int)($_POST['vmid'] ?? 0);
$action = (string)($_POST['action'] ?? '');
// optional: hier deine Dashboard-Auth checken!
if ($vmid <= 0) throw new InvalidArgumentException("vmid fehlt/ungültig");
if ($vmid <= 0) throw new InvalidArgumentException("vmid fehlt/ungültig");
$upid = $pve->powerAction($vmid, $action);
echo json_encode(['ok' => true, 'vmid' => $vmid, 'action' => $action, 'upid' => $upid]);
$upid = $pve->powerAction($vmid, $action);
echo json_encode(['ok' => true, 'vmid' => $vmid, 'action' => $action, 'upid' => $upid]);
} catch (Throwable $e) {
http_response_code(400);
echo json_encode(['ok' => false, 'error' => $e->getMessage()]);
http_response_code(400);
echo json_encode(['ok' => false, 'error' => $e->getMessage()]);
}