hosting

POST /v1/sites/{siteId}/wordpress/cli

Run one allow-listed WP-CLI command on the site.

Бүх hosting төгсгөлийн цэгүүд

Хөгжүүлэгчийн бүх баримт бичиг

Баталгаажуулалт

API түлхүүрийг bearer token хэлбэрээр илгөэнэ үү. Түлхүүр нь sites.view эрхтэй байх ёстой бөгөөд үүнгүйгээр 404 биш, харин 403 алдаа буцааж татгалзах болно.

Энэ төгсгөл цэг нь ямар ч байгууллагын ID шаардахгүй. Таны түлхүүр аль хэдийн харьяалагдах байгууллагыг тодорхойлж байгаа бөгөөд хариу нь тухайн байгууллагын хүрээнд хязгаарлагдана.

Туршиж үзэх

Өнцөг хаалтанд байгаа бүх зүйлийг өөрийн утгаар солиж, түлхүүр санамж байрлуулагчийг хяналтын самбарынхаа түлхүүрээр сольж оруулна уу.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/wordpress/cli \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "command": <string> }'

Та нэвтэрсэн байна уу? Таны хяналтын самбар дахь API консол нь таны бодит байгууллагын ID болон өөрийн түлхүүрийг автоматаар бөглөж, шууд ажиллаж буй API рүү хүсэлт илгээх тул та бодит хариуг харах боломжтой болно. Энэ төгсгөлийн цэгийг API консол дээр нээх

Дэлгэрэнгүй

An audited WP-CLI console. Every invocation is recorded in the site's WordPress activity log with its argv and exit code — never its output. ⛔ Allow-listed, never arbitrary. An unrestricted passthrough is remote code execution as the site user: wp eval runs arbitrary PHP, wp db query runs arbitrary SQL, and wp --require=/tmp/x.php loads code the caller chose before WP-CLI decides what to do. The permitted commands are reads and idempotent cache operations, listed by listWordPressCliCommands; anything else answers 422 naming the whole list. ⛔ config get and config list are deliberately absent — they read wp-config.php, whose constants include the database password and the authentication salts. ⛔ A non-zero exit_code still answers 200. The console's product is what WP-CLI said, and mapping a bad argument onto a 4xx would put our error page over the diagnosis the customer asked for. A 422 means we refused the command, which is a different answer. ⛔ The command travels in the body, not the path, so it never reaches a proxy or edge access log — option get names options a plugin may have stored a credential in. ⛔ Fleet only — refused where wp_cli is false. Requires sites.view and sites.panel_access.

Параметрүүд

НэрТөрөлЗаавал шаардлагатайЭнэ юу вэ
siteId (path)UuidТиймSite ID (UUIDv7).

Хүсэлтийн бие

НэрТөрөлЗаавал шаардлагатайЭнэ юу вэ
commandstringТиймThe WP-CLI command, with or without a leading wp.

Хариу үйлдэл

НэрТөрөлЗаавал шаардлагатайЭнэ юу вэ
argvstring[]ТиймWhat actually ran, after the allow-list normalised it — echoed back so wp plugin list and plugin list are visibly the same command.
exit_codeintegerТиймWP-CLI's exit code. 0 is success.
stdoutstringТиймWhat WP-CLI printed, up to the console's cap.
stderrstringТиймWP-CLI's diagnostics, carried separately and never merged into stdout — WP-CLI writes PHP notices here on runs that succeed, so folding them together would corrupt the JSON…
truncatedbooleanТиймTrue when stdout was cut at the cap. ⛔ Stated rather than hidden: a silently cut-off JSON document is worse than none, because it nearly parses.

Энэ төгсгөл цэгээс буцааж болох алдаанууд

401 · 403 · 404 · 422 · 429 · 503