hosting

POST /v1/sites/{siteId}/protection/directories/remove

Take the password off a folder on a site.

すべての hosting エンドポイント

認証

ベアラー トークンとして API キーを送信します。キーには sites.view 権限が付与されている必要があります。権限のないキーは 404 ではなく 403 で拒否されます。

このエンドポイントは組織IDを受け付けません。お使いのキーによって所属する組織がすでに特定されており、レスポンスはその組織にスコープされます。

試してみる

アングルブラケット内のすべてをご自身の値に置き換え、キーのプレースホルダーをご利用中のダッシュボードのキーに置き換えてください。

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/protection/directories/remove \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "directory": <string> }'

ログインしていますか?ダッシュボード内のAPIコンソールでは、実際の組織IDやお客様ご自身のキーが自動入力され、ライブAPIに対してリクエストが実行されるため、実際のレスポンスを確認することができます。 API コンソールでこのエンドポイントを開く

詳細

Removes the folder's HTTP password. Everything in it becomes publicly readable again the moment this returns, so the client names the folder back before calling. ⛔ A `POST` to a `/remove` sub-path rather than a `DELETE` with the folder in the URL, and the folder travels in the **body**: a directory contains slashes, and a percent-encoded `/` inside a path segment is rejected or silently decoded by enough proxies that it is not a contract worth betting a security control on. The whole protection state comes back, so the card re-renders from the server's answer. `404` for a site with no vendor hosting package. Requires `sites.view` and `sites.panel_access`.

パラメータ

名前タイプ必須これがその内容です
siteId (path)UuidはいSite ID (UUIDv7).

リクエスト本文

名前タイプ必須これがその内容です
directorystringはいThe folder, exactly as `SiteProtection.directories` reports it. Normalised the same way on both sides, so the folder that is unprotected is the one that was named.

返信

名前タイプ必須これがその内容です
countriesstring[]はいThe countries in the rule, as ISO 3166-1 alpha-2 codes.
countries_allow_onlybooleanはい⛔ `true` means `countries` is an **allow**-list: only those countries reach the site. Its own field rather than a mode string, because inverting it inverts who can reach the cus…
blocked_addressesstring[]はいThe blocked addresses and CIDR ranges, canonicalised — what is here is what is in force, not what was typed.
visitor_blocking_permittedbooleanはいWhether the package type permits blocking visitors at all. One flag governs both lists.
hotlink_configuredbooleanはいWhether any hotlink rule exists. ⛔ `false` means *no rules have been set up* — **not** "protection is on with no allowed hosts", which would read as a site blocking everybody.
hotlink_allow_directbooleanはいWhether a request with no referrer is allowed through. **Null** when the vendor did not state it — distinct from `false`, because a toggle rendered from an unknown lies about th…
hotlink_allowed_hostnamesstring[]はいThe sites permitted to embed these files.
hotlink_redirect_urlstringはいWhere a refused request is sent instead, or `""` when it is simply refused.
hotlink_extensionsstring[]はいThe file extensions the rule covers, normalised without a leading dot.
hotlink_permittedbooleanはいWhether the package type includes hotlink protection.
directoriesSiteProtectedDirectory[]はいThe password-protected folders. ⛔ Read from a vendor field that documents `null` as *"the request could not complete"* — the opposite of "nothing is protected" — so an unreadabl…
password_protection_permittedbooleanはいWhether the package type includes password-protected directories.
malware_scan_permittedbooleanはいWhether the package type includes the vendor's malware scan — the capability behind `scanSite` on this deploy target.

このエンドポイントが返すエラー

401 · 403 · 404 · 409 · 422 · 429 · 503