hosting
POST /v1/sites/{siteId}/panel-sessions
Mint one single-use panel link, at the moment the customer clicks.
ການພິສູດຕົວຕົນ
ສົ່ງ API key ເປັນ bearer token. ຈຸດເຊື່ອມຕໍ່ (endpoint) ນີ້ບໍ່ໄດ້ລະບຸສິດອະນຸຍາດສະເພາະໃດໜຶ່ງໃນຂໍ້ກຳນົດ, ດັ່ງນັ້ນຈຶ່ງຄວນໃຫ້ສິດ key ຂອງທ່ານເທົ່າທີ່ຈຳເປັນໜ້ອຍທີ່ສຸດ ແລະ ກວດສອບການຕອບກັບ ໂດຍບໍ່ຄວນທາດເດົາເອົາເອງ.
ຈຸດເຊື່ອມຕໍ່ນີ້ບໍ່ໄດ້ຮັບ ID ອົງກອນ. ລະຫັດຂອງທ່ານໄດ້ລະບຸອົງກອນທີ່ມັນຂຶ້ນກັບແລ້ວ, ແລະ ຄໍາຕອບແມ່ນຖືກຈໍາກັດຂອບເຂດໄວ້ສໍາລັບອົງກອນນັ້ນ.
ລອງໃຊ້ເບິ່ງ
ປ່ຽນແທນທຸກຢ່າງທີ່ຢູ່ໃນວົງເລັບມຸມດ້ວຍຄ່າຂອງທ່ານເອງ, ແລະ ປ່ຽນແທນຕົວແທນບ່ອນວ່າງຄີດ້ວຍຄີຈາກແຜງຄວບຄຸມຂອງທ່ານ.
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/panel-sessions \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "tool": <string<phpmyadmin, filemanager, web_ide>> }'ເຂົ້າສູ່ລະບົບແລ້ວບໍ? ໂຄງສົນທະນາ API ໃນໜ້າັດສະຫຼອງຂອງທ່ານຈະຕື່ມຂໍ້ມູນລະຫັດອົງກອນຕົວຈິງ ແລະ ລະຫັດລັບສ່ວນຕົວຂອງທ່ານໂດຍອັດຕະໂນມັດ, ແລະ ປະຕິບັດການຮ້ອງຂໍຜ່ານ API ຕົວຈິງ ເພື່ອໃຫ້ທ່ານສາມາດເຫັນຜົນຕອບຮັບທີ່ແທ້ຈິງໄດ້. ເປີດຈຸດສິ້ນສຸດນີ້ໃນຄອນໂສລ API
ລາຍລະອຽດ
Returns a freshly minted single-use SSO link into one of the site's per-site tools — phpMyAdmin or the File Manager — for the caller to open immediately. Why this exists rather than reusing getSiteDatabase. The links that endpoint returns are single-use and expire in 180 seconds, deliberately: a panel link that still works tomorrow is a credential. Rendering one into an <a href> on page load therefore hands the customer something that is dead before they have read the card — they click four minutes later and are told the token expired, which reads to them as being asked to log in. This endpoint moves the mint to the click, so the token's whole life is one redirect. Same authority as getSiteDatabase: both sites.view and sites.panel_access, RLS-scoped on the narrower key, so holding sites.panel_access in one org can never mint a link for another org's site. An out-of-scope or unknown id is a 404, never a 403, so this cannot be used to discover that a site exists. POST because it is not idempotent: every call writes a new single-use token to the hosting box. A GET would be re-issued by a prefetch, a proxy or the back button, burning a token each time. A site with no panel to open is a 409 carrying the same sentence the Tools card shows — never a 200 with a null URL.
ພາຣາມິເຕີ
| ຊື່ | ປະເພດ | ຕ້ອງການ | ສິ່ງທີ່ມັນເປັນ |
|---|---|---|---|
siteId (path) | Uuid | ແມ່ນແລ້ວ | Site ID (UUIDv7). |
ເນື້ອຫາຂອງຄຳຮ້ອງ
| ຊື່ | ປະເພດ | ຕ້ອງການ | ສິ່ງທີ່ມັນເປັນ |
|---|---|---|---|
tool | string<phpmyadmin, filemanager, web_ide> | ແມ່ນແລ້ວ | phpmyadmin opens the site's own database; filemanager opens the site's own home directory; web_ide opens VS Code in the browser against the site's files. A closed set on… |
ຖືກໂຈະ
| ຊື່ | ປະເພດ | ຕ້ອງການ | ສິ່ງທີ່ມັນເປັນ |
|---|---|---|---|
url | string | ແມ່ນແລ້ວ | The HTTPS single-use SSO link. Never null on a 200 — a site with no panel to open is a 409. |
reason | string | ບໍ່ | Empty on success; present so one client component can render both shapes. |
ຂໍ້ຜິດພາດທີ່ຈຸດເຊື່ອມຕໍ່ນີ້ສາມາດສົ່ງຄືນໄດ້
401 · 403 · 404 · 409 · 422 · 429