hosting
POST /v1/sites/{siteId}/protection/directories/remove
Take the password off a folder on a site.
Autentizace
Zašlete API klíč jako nosný token (bearer token). Klíč musí mít oprávnění sites.view; klíč bez něj je odmítnut s kódem 403, nikoli 404.
Tento koncový bod nevyžaduje žádné ID organizace. Váš klíč již identifikuje organizaci, ke které patří, a odpověď je na ni omezena.
Vyzvednout
Nahraďte cokoli v závorkách vlastními hodnotami a zástupný symbol klíče klíčem z vašeho řídicího panelu.
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/protection/directories/remove \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "directory": <string> }'Přihlášeni? Konzole API ve vašem dashboardu automaticky doplní vaše skutečné ID organizace i váš vlastní klíč a odešle požadavek na živé API, abyste viděli reálnou odpověď. Otevřete tento koncový bod v konzoli API
Podrobnosti
Removes the folder's HTTP password. Everything in it becomes publicly readable again the moment this returns, so the client names the folder back before calling. ⛔ A `POST` to a `/remove` sub-path rather than a `DELETE` with the folder in the URL, and the folder travels in the **body**: a directory contains slashes, and a percent-encoded `/` inside a path segment is rejected or silently decoded by enough proxies that it is not a contract worth betting a security control on. The whole protection state comes back, so the card re-renders from the server's answer. `404` for a site with no vendor hosting package. Requires `sites.view` and `sites.panel_access`.
Parametry
| Název | Typ | Požadováno | Co to je |
|---|---|---|---|
siteId (path) | Uuid | Ano | Site ID (UUIDv7). |
Tělo požadavku
| Název | Typ | Požadováno | Co to je |
|---|---|---|---|
directory | string | Ano | The folder, exactly as `SiteProtection.directories` reports it. Normalised the same way on both sides, so the folder that is unprotected is the one that was named. |
Odpověď
| Název | Typ | Požadováno | Co to je |
|---|---|---|---|
countries | string[] | Ano | The countries in the rule, as ISO 3166-1 alpha-2 codes. |
countries_allow_only | boolean | Ano | ⛔ `true` means `countries` is an **allow**-list: only those countries reach the site. Its own field rather than a mode string, because inverting it inverts who can reach the cus… |
blocked_addresses | string[] | Ano | The blocked addresses and CIDR ranges, canonicalised — what is here is what is in force, not what was typed. |
visitor_blocking_permitted | boolean | Ano | Whether the package type permits blocking visitors at all. One flag governs both lists. |
hotlink_configured | boolean | Ano | Whether any hotlink rule exists. ⛔ `false` means *no rules have been set up* — **not** "protection is on with no allowed hosts", which would read as a site blocking everybody. |
hotlink_allow_direct | boolean | Ano | Whether a request with no referrer is allowed through. **Null** when the vendor did not state it — distinct from `false`, because a toggle rendered from an unknown lies about th… |
hotlink_allowed_hostnames | string[] | Ano | The sites permitted to embed these files. |
hotlink_redirect_url | string | Ano | Where a refused request is sent instead, or `""` when it is simply refused. |
hotlink_extensions | string[] | Ano | The file extensions the rule covers, normalised without a leading dot. |
hotlink_permitted | boolean | Ano | Whether the package type includes hotlink protection. |
directories | SiteProtectedDirectory[] | Ano | The password-protected folders. ⛔ Read from a vendor field that documents `null` as *"the request could not complete"* — the opposite of "nothing is protected" — so an unreadabl… |
password_protection_permitted | boolean | Ano | Whether the package type includes password-protected directories. |
malware_scan_permitted | boolean | Ano | Whether the package type includes the vendor's malware scan — the capability behind `scanSite` on this deploy target. |
Chyby, které může tento koncový bod vrátit
401 · 403 · 404 · 409 · 422 · 429 · 503