hosting
GET /v1/sites/{siteId}/wordpress/update-policy
What this site is set to update by itself, and where it has drifted.
Аутентификация
Отправьте ключ API в качестве токена носителя (bearer token). Ключ должен иметь разрешение sites.view; ключ без него отклоняется с кодом 403, а не 404.
Этот эндпоинт не принимает идентификатор организации. Ваш ключ уже определяет организацию, к которой он принадлежит, и ответ ограничивается ее рамками.
Попробовать
Замените всё в угловых скобках на собственные значения, а плейсхолдер ключа — на ключ из вашей панели управления.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/wordpress/update-policy \
-H "Authorization: Bearer zdk_live_…"Вошли в систему? Консоль API в вашей панели управления автоматически подставляет реальный идентификатор вашей организации и ваш собственный ключ, а также выполняет запрос к работающему API, чтобы вы могли увидеть актуальный ответ. Откройте эту конечную точку в API-консоли
Подробнее
Returns three things that must never be collapsed into one: the **policy** an operator stored, what the site is **actually** configured to do, and the **drift** between them. ⛔ A screen showing only the stored policy cannot tell a customer that the policy was never applied — which is the whole point. A decision is applied when a row changes, and the row that decides whether a WordPress updates itself lives on that WordPress, not in this platform's database. A customer can change any of it from wp-admin, a plugin can change it on activation, and a restored backup carries the old settings back. ⛔ `observed_core` is `""` when `WP_AUTO_UPDATE_CORE` is **not defined at all**, which is NOT the same as `off` — an undefined constant means WordPress applies its own default, which is `minor`. Rendering the first as the second would tell an operator their sites are not taking security releases when in fact they are. ⛔ `observed_read` is `false` when the site could not be read (a managed hosting package, or a box that did not answer). An empty `drift` is only meaningful while it is `true`; otherwise an unreachable site renders as compliant, which is the worst default for a security setting. Ungated read — requires `sites.view`.
Параметры
| Имя | Тип | Обязательно | Что это |
|---|---|---|---|
siteId (path) | Uuid | Да | Site ID (UUIDv7). |
Ответ
| Имя | Тип | Обязательно | Что это |
|---|---|---|---|
core | string<off, minor, all> | Да | The stored policy for WordPress core updates. |
plugins | boolean | Да | The stored policy — whether every plugin should auto-update. |
themes | boolean | Да | The stored policy — whether every theme should auto-update. |
ring | string<canary, early, general> | Да | The staged-rollout ring this site belongs to. |
applied_at | string | Да | When the policy last reached the site, ISO-8601, or `""` if it never has. ⛔ A timestamp and not a flag: "when did this last reach the site" is the question an operator asks, and… |
apply_error | string | Да | Why the last apply failed, or `""`. Kept beside `applied_at` rather than replacing it, so a failed re-apply does not erase that an earlier one worked. |
observed_read | boolean | Да | Whether the site itself was read. ⛔ An empty `drift` is only meaningful while this is `true`. |
observed_core | string | Да | What `WP_AUTO_UPDATE_CORE` is set to on the site — `off`, `minor`, `all`, or `""` meaning **the constant is not defined at all**, so WordPress applies its own default. ⛔ `""` is… |
plugins_off | string[] | Да | The plugins on this site that are NOT auto-updating. |
themes_off | string[] | Да | The themes on this site that are NOT auto-updating. |
drift | string<core, plugins, themes>[] | Да | Which of `core`, `plugins`, `themes` the site disagrees with the policy about. |
Ошибки, которые может возвращать этот эндпоинт
401 · 403 · 404 · 429 · 503