hosting
POST /v1/sites/{siteId}/security/scan
Scan a site for malware now.
Authentification
Envoyez une clé d'API en tant que jeton du porteur (bearer token). Cet endpoint n'indique pas de permission spécifique dans la spécification, attribuez donc à votre clé le minimum requis et vérifiez la réponse plutôt que de faire des suppositions.
Cet endpoint ne prend aucun identifiant d'organisation. Votre clé identifie déjà l'organisation à laquelle elle appartient, et la réponse y est limitée.
Essayer
Remplacez tout ce qui se trouve entre crochets par vos propres valeurs, et le espace réservé à la clé par une clé de votre tableau de bord.
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/security/scan \
-H "Authorization: Bearer zdk_live_…"Connecté ? La console d'API de votre tableau de bord saisit votre véritable ID d'organisation ainsi que votre propre clé, et exécute la requête sur l'API de production afin que vous puissiez voir la réponse réelle. Ouvrir ce point de terminaison dans la console API
Détails
Queues an on-demand scan and answers 202 with the site's state, which will read scanning once the workflow starts. Gated on sites.view, not on a write key: asking for a fresh scan of your own site changes nothing about it, and it is the first thing a worried customer does. Concurrency is bounded by the workflow id, which is per site. A second request while a scan is running is still a 202 — a scan of this site is in progress, which is what was asked for — and no second scan of the same document root starts. 422 when the site is not running (a suspended or still-provisioning site has no document root to scan). 503 when the durable-execution service is unreachable: answering 202 there would flip the card to scanning… for a scan that was never started, and the customer would watch a spinner for hours.
Paramètres
| Nom | Type | Obligatoire | Qu'est-ce que c'est |
|---|---|---|---|
siteId (path) | Uuid | Oui | Site ID (UUIDv7). |
Réponse
| Nom | Type | Obligatoire | Qu'est-ce que c'est |
|---|---|---|---|
status | MalwareStatus | Oui | A site's scan verdict. There is deliberately no unscanned member: a site nothing has looked at yet is clean with last_scan_at: null, which is one nullable timestamp… |
last_scan_at | object | Oui | When a scan last completed. null = never scanned. A scan that failed does not stamp this, so a stale success can never be mistaken for a fresh one. |
detections | MalwareDetection[] | Oui | — |
recent_resolutions | ResolvedMalwareDetection[] | Oui | Findings that were present and are not any more, most recently cleared first — the record of the protection having worked, which an all-clear alone cannot show. resolved_at… |
can_rescan | boolean | Oui | Whether rescanSite will accept a request for this site: false while a scan is already running, false for a site that is not running at all (there is no document root to scan),… |
last_scan_error_code | string<, scan_conflict, scanner_unreachable, scanner_missing, scan_failed> | Oui | Why a scan that ran could not finish; empty when none has failed. Non-empty means an attempt was made against this site and broke — an unreachable host, a vendor error, a scan… |
unavailable_reason | string | Oui | Why no scan was attempted; empty when one was. A stable machine identifier for the client to localise, never a sentence and never a vendor name. vendor_unsupported — the… |
runtime | SiteRuntimeSecurity | Oui | What our runtime sensor saw happen on this site, and whether anything was watching it at all. The malware fields above are a verdict on files at rest; this is the other half —… |
Erreurs que cet point de terminaison peut renvoyer
401 · 403 · 404 · 422 · 429 · 503