false, 'error' => 'Unauthorized']); exit; } if (($_SESSION['role'] ?? 'user') !== 'admin') { http_response_code(403); header('Content-Type: application/json; charset=utf-8'); echo json_encode(['ok' => false, 'error' => 'Forbidden']); exit; } require_once __DIR__ . '/../lib/PveApi.php'; $cfg = require __DIR__ . '/../config/pve.php'; $pve = new PveApi($cfg); header('Content-Type: application/json; charset=utf-8'); try { if ($_SERVER['REQUEST_METHOD'] !== 'POST') { http_response_code(405); echo json_encode(['ok' => false, 'error' => 'Method not allowed']); exit; } $vmid = (int)($_POST['vmid'] ?? 0); $action = (string)($_POST['action'] ?? ''); if ($vmid <= 0) throw new InvalidArgumentException("vmid fehlt/ungültig"); $upid = $pve->powerAction($vmid, $action); echo json_encode(['ok' => true, 'vmid' => $vmid, 'action' => $action, 'upid' => $upid]); } catch (Throwable $e) { http_response_code(400); echo json_encode(['ok' => false, 'error' => $e->getMessage()]); }