인증
Bearer 토큰으로 API 키를 전송하세요. 이 엔드포인트는 명세에 특정 권한을 명시하지 않으므로, 가정하기보다는 키에 필요한 최소한의 권한을 부여하고 응답을 확인하세요.
이 엔드포인트는 조직 ID를 받지 않습니다. 사용자의 키가 이미 속한 조직을 식별하며, 응답은 해당 조직으로 한정됩니다.
무료 체험하기
대괄호 안에 있는 모든 내용을 사용자 지정 값으로 바꾸고, 키 플레이스홀더는 대시보드의 키로 바꾸세요.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/security \
-H "Authorization: Bearer zdk_live_…"로그인하셨나요? 대시보드의 API 콘솔이 실제 조직 ID와 본인의 키를 자동으로 채우고 라이브 API를 대상으로 요청을 실행하므로 실제 응답을 확인할 수 있습니다. API 콘솔에서 이 엔드포인트를 여세요
상세 정보
The per-site Tools tab's *Malware and security* card — the scan verdict, when it last completed, and every live finding. RLS-scoped to a site the caller can view (`sites.view`); an out-of-scope or unknown id is a `404`, exactly like `getSite`. **This reads a stored projection and never calls the scanner.** The card mounts with the Tools tab for every site and polls while a scan is in flight, so a vendor round-trip here would be an un-cached external call in a hot path (CLAUDE.md §2.16). A scan is a durable Temporal workflow (§2.9) that writes the row this returns. `status: clean` with `last_scan_at: null` means **not scanned yet** — one nullable timestamp rather than a fourth status. "We could not look" is deliberately distinguishable from "we looked and it is fine", because neither a failed nor an un-attempted scan stamps `last_scan_at`. ⛔ **"We tried and could not" and "we have never tried" are different facts and arrive in different fields.** `last_scan_error` carries the first (an attempt ran and broke — an unreachable host, a vendor error, a scan abandoned after timing out); `unavailable_reason` carries the second as a machine identifier (nothing is attached to scan this site, or its platform cannot be scanned at all). They are never both non-empty. Render the first as a warning and the second as a neutral notice: showing *"we couldn't scan this site"* over a scan that was never attempted tells a customer their site might be infected when nothing of the sort is known. `detections[].path` is always **relative to the document root** — an absolute path would disclose the host account handle and the fleet's filesystem layout (§2.4).
매개변수
| 이름 | 유형 | 필수 | 설명 |
|---|---|---|---|
siteId (path) | Uuid | 예 | Site ID (UUIDv7). |
응답
| 이름 | 유형 | 필수 | 설명 |
|---|---|---|---|
status | MalwareStatus | 예 | A site's scan verdict. There is deliberately **no** `unscanned` member: a site nothing has looked at yet is `clean` with `last_scan_at: null`, which is one nullable timestamp ra… |
last_scan_at | object | 예 | When a scan last **completed**. `null` = never scanned. A scan that failed does not stamp this, so a stale success can never be mistaken for a fresh one. |
detections | MalwareDetection[] | 예 | — |
recent_resolutions | ResolvedMalwareDetection[] | 예 | Findings that were present and are not any more, most recently cleared first — the record of the protection having worked, which an all-clear alone cannot show. `resolved_at` al… |
can_rescan | boolean | 예 | Whether `rescanSite` will accept a request for this site: false while a scan is already running, false for a site that is not running at all (there is no document root to scan),… |
last_scan_error_code | string<, scan_conflict, scanner_unreachable, scanner_missing, scan_failed> | 예 | Why a scan that **ran** could not finish; empty when none has failed. Non-empty means an attempt was made against this site and broke — an unreachable host, a vendor error, a sc… |
unavailable_reason | string | 예 | Why **no scan was attempted**; empty when one was. A stable machine identifier for the client to localise, never a sentence and never a vendor name. `vendor_unsupported` — the h… |
runtime | SiteRuntimeSecurity | 예 | What our runtime sensor saw **happen** on this site, and whether anything was watching it at all. The malware fields above are a verdict on files at rest; this is the other half… |
이 엔드포인트가 반환할 수 있는 오류
401 · 403 · 404 · 429