- Added authentication checks to pve_action.php and pve_list.php - Require valid logged-in session before API access - Restrict Proxmox actions to admin users only - Return HTTP 401 for unauthenticated requests - Return HTTP 403 for unauthorized users - Keep existing API logic unchanged