hosting

POST /v1/sites/{siteId}/wordpress/cli

Run one allow-listed WP-CLI command on the site.

Dhammaan hosting bixiyayaasha

Xaqiijinta aqoonsiga

U dir furaha API ah calaamad dusha ah (bearer token). Furaha waa inuu wataa ruqadda sites.view; furaha aan wadan waxaa loo diidayaa 403, ee ma aha 404.

Boggan ma qaato aqoonsiga ururka. Furahaagu wuxuu horay u aqoonsanayaa ururka uu ka tirsan yahay, jawaabtuna waxay ku kooban tahay halkaas.

Isku day

Ku beddel wax kasta oo ku dhex jira qeebaha xaglaha ah qiimayaashaada, sidoo kalena haystaaha furaha ku beddel fure ka dhex muuqda dashboordigaaga.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/wordpress/cli \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "command": <string> }'

Ma sign-garaysay? Qalabka API ee ku jira dashboard-kaagu wuxuu buuxiyaa aqoonsigaaga ururka ee dhabta ah iyo furahaaga gaarka ah, wuxuuna ku shaqeysiiyaa codsiga API-ga nool si aad u aragto jawaabta dhabta ah. Kani ka fur barta kontoroolka ee API

Faahfaahin

An audited WP-CLI console. Every invocation is recorded in the site's WordPress activity log with its argv and exit code — never its output. ⛔ **Allow-listed, never arbitrary.** An unrestricted passthrough is remote code execution as the site user: `wp eval` runs arbitrary PHP, `wp db query` runs arbitrary SQL, and `wp --require=/tmp/x.php` loads code the caller chose before WP-CLI decides what to do. The permitted commands are reads and idempotent cache operations, listed by `listWordPressCliCommands`; anything else answers `422` naming the whole list. ⛔ `config get` and `config list` are **deliberately absent** — they read `wp-config.php`, whose constants include the database password and the authentication salts. ⛔ A **non-zero `exit_code` still answers `200`.** The console's product is what WP-CLI said, and mapping a bad argument onto a 4xx would put our error page over the diagnosis the customer asked for. A `422` means *we* refused the command, which is a different answer. ⛔ The command travels in the **body**, not the path, so it never reaches a proxy or edge access log — `option get` names options a plugin may have stored a credential in. ⛔ **Fleet only** — refused where `wp_cli` is `false`. Requires `sites.view` and `sites.panel_access`.

Cabiraha

MagacaNoocLoo baahan yahayMaxay tahay
siteId (path)UuidHaaSite ID (UUIDv7).

Codsiga jidhkiisa

MagacaNoocLoo baahan yahayMaxay tahay
commandstringHaaThe WP-CLI command, with or without a leading `wp`.

Jawaab

MagacaNoocLoo baahan yahayMaxay tahay
argvstring[]HaaWhat actually ran, after the allow-list normalised it — echoed back so `wp plugin list` and `plugin list` are visibly the same command.
exit_codeintegerHaaWP-CLI's exit code. `0` is success.
stdoutstringHaaWhat WP-CLI printed, up to the console's cap.
stderrstringHaaWP-CLI's diagnostics, carried **separately** and never merged into `stdout` — WP-CLI writes PHP notices here on runs that succeed, so folding them together would corrupt the JSO…
truncatedbooleanHaaTrue when `stdout` was cut at the cap. ⛔ Stated rather than hidden: a silently cut-off JSON document is worse than none, because it nearly parses.

Cilladaha ay bartaani soo celin karto

401 · 403 · 404 · 422 · 429 · 503