hosting

GET /v1/sites/{siteId}/protection

Get every protection control for a site.

Все эндпоинты hosting

Вся документация для разработчиков

Аутентификация

Отправьте ключ API в качестве токена носителя (bearer token). Ключ должен иметь разрешение sites.view; ключ без него отклоняется с кодом 403, а не 404.

Этот эндпоинт не принимает идентификатор организации. Ваш ключ уже определяет организацию, к которой он принадлежит, и ответ ограничивается ее рамками.

Попробовать

Замените всё в угловых скобках на собственные значения, а плейсхолдер ключа — на ключ из вашей панели управления.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/protection \
  -H "Authorization: Bearer zdk_live_…"

Вошли в систему? Консоль API в вашей панели управления автоматически подставляет реальный идентификатор вашей организации и ваш собственный ключ, а также выполняет запрос к работающему API, чтобы вы могли увидеть актуальный ответ. Откройте эту конечную точку в API-консоли

Подробнее

Blocked countries, blocked addresses, hotlink rules and password-protected folders, in one read. One endpoint rather than four, deliberately: each vendor read costs a driver build and an HTTP transport, the card renders all four together, and four endpoints would be four transports and four package lookups per render on an API that rate-limits per source IP (§2.16). The *_permitted flags travel with the state so a screen never offers a control whose request is already known to be refused. hotlink_allow_direct is null when the vendor did not state it — distinct from false, because a toggle rendered from an unknown lies about the customer's site. 404 for a site with no vendor hosting package. Requires sites.view.

Параметры

ИмяТипОбязательноЧто это
siteId (path)UuidДаSite ID (UUIDv7).

Ответ

ИмяТипОбязательноЧто это
countriesstring[]ДаThe countries in the rule, as ISO 3166-1 alpha-2 codes.
countries_allow_onlybooleanДаtrue means countries is an allow-list: only those countries reach the site. Its own field rather than a mode string, because inverting it inverts who can reach the…
blocked_addressesstring[]ДаThe blocked addresses and CIDR ranges, canonicalised — what is here is what is in force, not what was typed.
visitor_blocking_permittedbooleanДаWhether the package type permits blocking visitors at all. One flag governs both lists.
hotlink_configuredbooleanДаWhether any hotlink rule exists. ⛔ false means no rules have been set upnot "protection is on with no allowed hosts", which would read as a site blocking everybody.
hotlink_allow_directbooleanДаWhether a request with no referrer is allowed through. Null when the vendor did not state it — distinct from false, because a toggle rendered from an unknown lies about the…
hotlink_allowed_hostnamesstring[]ДаThe sites permitted to embed these files.
hotlink_redirect_urlstringДаWhere a refused request is sent instead, or "" when it is simply refused.
hotlink_extensionsstring[]ДаThe file extensions the rule covers, normalised without a leading dot.
hotlink_permittedbooleanДаWhether the package type includes hotlink protection.
directoriesSiteProtectedDirectory[]ДаThe password-protected folders. ⛔ Read from a vendor field that documents null as "the request could not complete" — the opposite of "nothing is protected" — so an unreadable…
password_protection_permittedbooleanДаWhether the package type includes password-protected directories.
malware_scan_permittedbooleanДаWhether the package type includes the vendor's malware scan — the capability behind scanSite on this deploy target.

Ошибки, которые может возвращать этот эндпоинт

401 · 403 · 404 · 429 · 503