hosting
PUT /v1/sites/{siteId}/protection/hotlink
Replace a site's hotlink-protection rules.
認証
ベアラー トークンとして API キーを送信します。キーには sites.view 権限が付与されている必要があります。権限のないキーは 404 ではなく 403 で拒否されます。
このエンドポイントは組織IDを受け付けません。お使いのキーによって所属する組織がすでに特定されており、レスポンスはその組織にスコープされます。
試してみる
アングルブラケット内のすべてをご自身の値に置き換え、キーのプレースホルダーをご利用中のダッシュボードのキーに置き換えてください。
curl -X PUT https://api.zinndigital.com/v1/sites/{siteId}/protection/hotlink \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "allow_direct": <boolean>, "allowed_hostnames": <string[]>, "extensions": <string[]> }'ログインしていますか?ダッシュボード内のAPIコンソールでは、実際の組織IDやお客様ご自身のキーが自動入力され、ライブAPIに対してリクエストが実行されるため、実際のレスポンスを確認することができます。 API コンソールでこのエンドポイントを開く
詳細
Decides who may embed the site's files from another site. `allowed_hostnames` are the sites permitted to do so; `extensions` are the file types the rule covers; `redirect_url` is where a refused request is sent instead, and an empty string means the request is simply refused. A replace rather than a patch, for the same reason as the two block lists: the vendor endpoint replaces the set. Extensions are normalised before they are sent — a leading dot and capitals are stripped — so what the customer typed and what is enforced cannot differ. `404` for a site with no vendor hosting package. Requires `sites.view` and `sites.panel_access`.
パラメータ
| 名前 | タイプ | 必須 | これがその内容です |
|---|---|---|---|
siteId (path) | Uuid | はい | Site ID (UUIDv7). |
リクエスト本文
| 名前 | タイプ | 必須 | これがその内容です |
|---|---|---|---|
allow_direct | boolean | はい | Whether a request with no referrer — somebody opening the file's URL directly, and every search-engine image crawler — is allowed through. |
allowed_hostnames | string[] | はい | The sites permitted to embed these files. The customer's own domain is included by the vendor; list the others. |
redirect_url | string | いいえ | Where a refused request is sent instead. Empty means the request is refused outright rather than redirected. |
extensions | string[] | はい | The file extensions the rule covers, without a leading dot. An empty array means the rule covers nothing and is therefore off. |
返信
| 名前 | タイプ | 必須 | これがその内容です |
|---|---|---|---|
countries | string[] | はい | The countries in the rule, as ISO 3166-1 alpha-2 codes. |
countries_allow_only | boolean | はい | ⛔ `true` means `countries` is an **allow**-list: only those countries reach the site. Its own field rather than a mode string, because inverting it inverts who can reach the cus… |
blocked_addresses | string[] | はい | The blocked addresses and CIDR ranges, canonicalised — what is here is what is in force, not what was typed. |
visitor_blocking_permitted | boolean | はい | Whether the package type permits blocking visitors at all. One flag governs both lists. |
hotlink_configured | boolean | はい | Whether any hotlink rule exists. ⛔ `false` means *no rules have been set up* — **not** "protection is on with no allowed hosts", which would read as a site blocking everybody. |
hotlink_allow_direct | boolean | はい | Whether a request with no referrer is allowed through. **Null** when the vendor did not state it — distinct from `false`, because a toggle rendered from an unknown lies about th… |
hotlink_allowed_hostnames | string[] | はい | The sites permitted to embed these files. |
hotlink_redirect_url | string | はい | Where a refused request is sent instead, or `""` when it is simply refused. |
hotlink_extensions | string[] | はい | The file extensions the rule covers, normalised without a leading dot. |
hotlink_permitted | boolean | はい | Whether the package type includes hotlink protection. |
directories | SiteProtectedDirectory[] | はい | The password-protected folders. ⛔ Read from a vendor field that documents `null` as *"the request could not complete"* — the opposite of "nothing is protected" — so an unreadabl… |
password_protection_permitted | boolean | はい | Whether the package type includes password-protected directories. |
malware_scan_permitted | boolean | はい | Whether the package type includes the vendor's malware scan — the capability behind `scanSite` on this deploy target. |
このエンドポイントが返すエラー
401 · 403 · 404 · 409 · 422 · 429 · 503