hosting
GET /v1/sites/{siteId}/wordpress/update-policy
What this site is set to update by itself, and where it has drifted.
المصادقة
أرسل مفتاح واجهة برمجة التطبيقات (API key) كرمز حامل (bearer token). يجب أن يحمل المفتاح إذن sites.view؛ والمفتاح الذي لا يملكه يُرفض بالرمز 403 وليس 404.
لا يقبل هذا الطرف أي معرف للمؤسسة. يحدد مفتاحك بالفعل المؤسسة التي ينتمي إليها، وتكون الاستجابة محصورة في نطاقها.
جربه الآن
استبدل أي شيء بين أقواس زاوية بقيمك الخاصة، والعنصر النائب للمفتاح بمفتاح من لوحة تحكمك.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/wordpress/update-policy \
-H "Authorization: Bearer zdk_live_…"هل سجلت الدخول؟ تقوم وحدة تحكم واجهة برمجة التطبيقات في لوحة التحكم الخاصة بك بربط معرف مؤسستك الحقيقي ومفتاحك الخاص، وتنفذ الطلب مقابل واجهة برمجة التطبيقات المباشرة لتتمكن من رؤية الاستجابة الفعلية. افتح هذه النهاية الطرفية في وحدة تحكم API
التفاصيل
Returns three things that must never be collapsed into one: the **policy** an operator stored, what the site is **actually** configured to do, and the **drift** between them. ⛔ A screen showing only the stored policy cannot tell a customer that the policy was never applied — which is the whole point. A decision is applied when a row changes, and the row that decides whether a WordPress updates itself lives on that WordPress, not in this platform's database. A customer can change any of it from wp-admin, a plugin can change it on activation, and a restored backup carries the old settings back. ⛔ `observed_core` is `""` when `WP_AUTO_UPDATE_CORE` is **not defined at all**, which is NOT the same as `off` — an undefined constant means WordPress applies its own default, which is `minor`. Rendering the first as the second would tell an operator their sites are not taking security releases when in fact they are. ⛔ `observed_read` is `false` when the site could not be read (a managed hosting package, or a box that did not answer). An empty `drift` is only meaningful while it is `true`; otherwise an unreachable site renders as compliant, which is the worst default for a security setting. Ungated read — requires `sites.view`.
المعلمات
| الاسم | النوع | مطلوب | ما هو هذا |
|---|---|---|---|
siteId (path) | Uuid | نعم | Site ID (UUIDv7). |
الاستجابة
| الاسم | النوع | مطلوب | ما هو هذا |
|---|---|---|---|
core | string<off, minor, all> | نعم | The stored policy for WordPress core updates. |
plugins | boolean | نعم | The stored policy — whether every plugin should auto-update. |
themes | boolean | نعم | The stored policy — whether every theme should auto-update. |
ring | string<canary, early, general> | نعم | The staged-rollout ring this site belongs to. |
applied_at | string | نعم | When the policy last reached the site, ISO-8601, or `""` if it never has. ⛔ A timestamp and not a flag: "when did this last reach the site" is the question an operator asks, and… |
apply_error | string | نعم | Why the last apply failed, or `""`. Kept beside `applied_at` rather than replacing it, so a failed re-apply does not erase that an earlier one worked. |
observed_read | boolean | نعم | Whether the site itself was read. ⛔ An empty `drift` is only meaningful while this is `true`. |
observed_core | string | نعم | What `WP_AUTO_UPDATE_CORE` is set to on the site — `off`, `minor`, `all`, or `""` meaning **the constant is not defined at all**, so WordPress applies its own default. ⛔ `""` is… |
plugins_off | string[] | نعم | The plugins on this site that are NOT auto-updating. |
themes_off | string[] | نعم | The themes on this site that are NOT auto-updating. |
drift | string<core, plugins, themes>[] | نعم | Which of `core`, `plugins`, `themes` the site disagrees with the policy about. |
الأخطاء التي يمكن أن تُرجعها نقطة النهاية هذه
401 · 403 · 404 · 429 · 503