hosting
GET /v1/sites/{siteId}/security
A site's malware state and live findings.
ការផ្ទៀងផ្ទាត់ភាពត្រឹមត្រូវ
ផ្ញើគ្រាប់ចុច API ជាតូកែន bearer ។ ចំណុចបញ្ចប់នេះមិនបញ្ជាក់ពីសិទ្ធិជាក់លាក់ណាមួយនៅក្នុងការបញ្ជាក់នោះទេ ដូច្នេះសូមផ្ដល់សិទ្ធិអប្បបរមាដែលគ្រាប់ចុចរបស់អ្នកត្រូវការ ហើយពិនិត្យមើលការឆ្លើយតបជំនួសឱ្យការសន្មត់។
ចំនុចបញ្ចប់នេះមិនត្រូវការលេខសម្គាល់ស្ថាប័នទេ។ ពស័្ដកូនរបស់អ្នករួចហើយកំណត់អត្តសញ្ញាណស្ថាប័នដែលវាជាកម្មសិទ្ធិ ហើយការឆ្លើយតបគឺត្រូវបានកំណត់វិសាលភាពទៅតាមនោះ។
សាកល្បង
ជំនួសអ្វីមួយនៅក្នុងសញ្ញាពងក្រពើ < > ដោយប្រើតម្លៃផ្ទាល់ខ្លួនរបស់អ្នក ហើយជំនួសកន្លែងរក្សាទុកសោដោយប្រើសោចេញពីផ្ទាំងគ្រប់គ្រងរបស់អ្នក។
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/security \
-H "Authorization: Bearer zdk_live_…"បានចូលគណនីរួចហើយមែនទេ? កុងសូល API ក្នុងផ្ទាំងគ្រប់គ្រងរបស់អ្នក បំពេញលេខសម្គាល់ស្ថាប័នពិតប្រាកដរបស់អ្នក និងសោផ្ទាល់ខ្លួនរបស់អ្នក ហើយដំណើរការសំណើទល់នឹង API ផ្ទាល់ ដូច្នេះអ្នកអាចមើលឃើញការឆ្លើយតបពិតប្រាកដ។ បើកចំណុចបញ្ចប់នេះក្នុងកុងសូល API
ព័ត៌មានលម្អិត
The per-site Tools tab's *Malware and security* card — the scan verdict, when it last completed, and every live finding. RLS-scoped to a site the caller can view (`sites.view`); an out-of-scope or unknown id is a `404`, exactly like `getSite`. **This reads a stored projection and never calls the scanner.** The card mounts with the Tools tab for every site and polls while a scan is in flight, so a vendor round-trip here would be an un-cached external call in a hot path (CLAUDE.md §2.16). A scan is a durable Temporal workflow (§2.9) that writes the row this returns. `status: clean` with `last_scan_at: null` means **not scanned yet** — one nullable timestamp rather than a fourth status. "We could not look" is deliberately distinguishable from "we looked and it is fine", because neither a failed nor an un-attempted scan stamps `last_scan_at`. ⛔ **"We tried and could not" and "we have never tried" are different facts and arrive in different fields.** `last_scan_error` carries the first (an attempt ran and broke — an unreachable host, a vendor error, a scan abandoned after timing out); `unavailable_reason` carries the second as a machine identifier (nothing is attached to scan this site, or its platform cannot be scanned at all). They are never both non-empty. Render the first as a warning and the second as a neutral notice: showing *"we couldn't scan this site"* over a scan that was never attempted tells a customer their site might be infected when nothing of the sort is known. `detections[].path` is always **relative to the document root** — an absolute path would disclose the host account handle and the fleet's filesystem layout (§2.4).
ប៉ារ៉ាម៉ែត្រ
| ឈ្មោះ | ប្រភេទ | តម្រូវការ | តើវាជាអ្វី |
|---|---|---|---|
siteId (path) | Uuid | បាទ/ចាស | Site ID (UUIDv7). |
ផ្អាកដំណើរការ
| ឈ្មោះ | ប្រភេទ | តម្រូវការ | តើវាជាអ្វី |
|---|---|---|---|
status | MalwareStatus | បាទ/ចាស | A site's scan verdict. There is deliberately **no** `unscanned` member: a site nothing has looked at yet is `clean` with `last_scan_at: null`, which is one nullable timestamp ra… |
last_scan_at | object | បាទ/ចាស | When a scan last **completed**. `null` = never scanned. A scan that failed does not stamp this, so a stale success can never be mistaken for a fresh one. |
detections | MalwareDetection[] | បាទ/ចាស | — |
recent_resolutions | ResolvedMalwareDetection[] | បាទ/ចាស | Findings that were present and are not any more, most recently cleared first — the record of the protection having worked, which an all-clear alone cannot show. `resolved_at` al… |
can_rescan | boolean | បាទ/ចាស | Whether `rescanSite` will accept a request for this site: false while a scan is already running, false for a site that is not running at all (there is no document root to scan),… |
last_scan_error_code | string<, scan_conflict, scanner_unreachable, scanner_missing, scan_failed> | បាទ/ចាស | Why a scan that **ran** could not finish; empty when none has failed. Non-empty means an attempt was made against this site and broke — an unreachable host, a vendor error, a sc… |
unavailable_reason | string | បាទ/ចាស | Why **no scan was attempted**; empty when one was. A stable machine identifier for the client to localise, never a sentence and never a vendor name. `vendor_unsupported` — the h… |
runtime | SiteRuntimeSecurity | បាទ/ចាស | What our runtime sensor saw **happen** on this site, and whether anything was watching it at all. The malware fields above are a verdict on files at rest; this is the other half… |
កំហុសដែលចំណុចបញ្ចប់នេះអាចបង្វិលត្រឡប់មកវិញ
401 · 403 · 404 · 429