hosting

PUT /v1/sites/{siteId}/protection/countries

Replace a site's country rule.

Todos os endpoints de hosting

Autenticação

Envie uma chave de API como um token de portador. A chave deve ter a permissão sites.view; uma chave sem ela é recusada com 403, e não 404.

Este endpoint não requer um ID de organização. Sua chave já identifica a organização à qual pertence, e a resposta é delimitada a ela.

Experimente

Substitua qualquer item entre colchetes por seus próprios valores e o espaço reservado para a chave por uma chave do seu painel.

curl -X PUT https://api.zinndigital.com/v1/sites/{siteId}/protection/countries \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "countries": <string[]> }'

Conectado? O console da API no seu painel preenche o ID da sua organização real e a sua própria chave, e executa a requisição contra a API de produção para que você possa ver a resposta real. Abra este endpoint no console da API

Detalhes

A **replace, not a patch**: the platform's endpoint replaces the list, and an empty list is its documented way to clear every country restriction — so *"unblock everywhere"* needs no second verb. ⛔ `allow_only` inverts who can reach the customer's site: `false` blocks the listed countries, `true` blocks everyone **except** them. It is its own boolean rather than a mode string precisely because a free-form word invites each consumer to re-derive that, and getting it backwards takes the site off the internet for everybody. A value that is not a two-letter country code is refused `422` before the vendor is called, with our sentence. `404` for a site with no vendor hosting package. Requires `sites.view` and `sites.panel_access`.

Parâmetros

NomeTipoObrigatórioO que é
siteId (path)UuidSimSite ID (UUIDv7).

Corpo da requisição

NomeTipoObrigatórioO que é
countriesstring[]SimThe whole rule, as two-letter ISO 3166-1 alpha-2 codes. An empty array clears the restriction entirely.
allow_onlybooleanNão`false` blocks the listed countries. `true` makes the list an **allow**-list — only those countries reach the site, and everyone else is blocked.

Resposta

NomeTipoObrigatórioO que é
countriesstring[]SimThe countries in the rule, as ISO 3166-1 alpha-2 codes.
countries_allow_onlybooleanSim⛔ `true` means `countries` is an **allow**-list: only those countries reach the site. Its own field rather than a mode string, because inverting it inverts who can reach the cus…
blocked_addressesstring[]SimThe blocked addresses and CIDR ranges, canonicalised — what is here is what is in force, not what was typed.
visitor_blocking_permittedbooleanSimWhether the package type permits blocking visitors at all. One flag governs both lists.
hotlink_configuredbooleanSimWhether any hotlink rule exists. ⛔ `false` means *no rules have been set up* — **not** "protection is on with no allowed hosts", which would read as a site blocking everybody.
hotlink_allow_directbooleanSimWhether a request with no referrer is allowed through. **Null** when the vendor did not state it — distinct from `false`, because a toggle rendered from an unknown lies about th…
hotlink_allowed_hostnamesstring[]SimThe sites permitted to embed these files.
hotlink_redirect_urlstringSimWhere a refused request is sent instead, or `""` when it is simply refused.
hotlink_extensionsstring[]SimThe file extensions the rule covers, normalised without a leading dot.
hotlink_permittedbooleanSimWhether the package type includes hotlink protection.
directoriesSiteProtectedDirectory[]SimThe password-protected folders. ⛔ Read from a vendor field that documents `null` as *"the request could not complete"* — the opposite of "nothing is protected" — so an unreadabl…
password_protection_permittedbooleanSimWhether the package type includes password-protected directories.
malware_scan_permittedbooleanSimWhether the package type includes the vendor's malware scan — the capability behind `scanSite` on this deploy target.

Erros que este endpoint pode retornar

401 · 403 · 404 · 409 · 422 · 429 · 503