hosting

POST /v1/sites/{siteId}/protection/directories

Password-protect a folder on a site.

모든 hosting 엔드포인트

인증

Bearer 토큰으로 API 키를 전송하세요. 키는 반드시 sites.view 권한을 가지고 있어야 하며, 권한이 없는 키는 404가 아닌 403으로 거부됩니다.

이 엔드포인트는 조직 ID를 받지 않습니다. 사용자의 키가 이미 속한 조직을 식별하며, 응답은 해당 조직으로 한정됩니다.

무료 체험하기

대괄호 안에 있는 모든 내용을 사용자 지정 값으로 바꾸고, 키 플레이스홀더는 대시보드의 키로 바꾸세요.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/protection/directories \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "directory": <string>, "username": <string> }'

로그인하셨나요? 대시보드의 API 콘솔이 실제 조직 ID와 본인의 키를 자동으로 채우고 라이브 API를 대상으로 요청을 실행하므로 실제 응답을 확인할 수 있습니다. API 콘솔에서 이 엔드포인트를 여세요

상세 정보

Puts an HTTP password on one folder under the document root. `POST` and not a `PUT` of the whole set even though the vendor endpoint replaces it: the set is rebuilt by the engine from the entries the platform itself returned, precisely because we do not hold the other folders' passwords and must not ask a customer to re-enter them to protect a new one. ⛔ **The response carries a password, and it is the only one on this surface that does.** Omit `password` and the engine generates a strong one; either way the value is returned **exactly once**, written to no record of ours, and readable back by no endpoint. The whole response is therefore a credential: a client displays it once and does not cache it, store it in a query cache, put it in a URL, or include it in an error report. `username` may not contain a colon or a space — `:` separates the name from the hash in an `.htpasswd` file, so a name containing one produces a file that parses into something other than what was written. `404` for a site with no vendor hosting package. Requires `sites.view` and `sites.panel_access`.

매개변수

이름유형필수설명
siteId (path)UuidSite ID (UUIDv7).

요청 본문

이름유형필수설명
directorystringThe folder to protect, relative to the document root. It is normalised before it is compared with what the vendor holds, so what is protected is the folder the customer meant.
usernamestringThe name a visitor types. No colon and no space, because this is written into an `.htpasswd` file where `:` is the field separator.
passwordstring아니요Optional. Omitting it means *generate one for me*, which is the path that guarantees a strong value. Write-only: whatever is sent here appears in no response, no log line and no…

응답

이름유형필수설명
directorySiteProtectedDirectoryThe folder, exactly as `getSiteProtection` will report it.
passwordstringThe password, shown once. Deliberately carries no example — a documented example of a credential field is the shape people copy. ⛔ It never contains a colon: this value is writt…

이 엔드포인트가 반환할 수 있는 오류

401 · 403 · 404 · 409 · 422 · 429 · 503