hosting
GET /v1/sites/{siteId}/security
A site's malware state and live findings.
Autentifikimi
Drgoni një çelës API si një token mbajtës. Ky pikëndalim nuk specifikon një leje specifike në specifikim, prandaj jepini çelësit tuaj minimumin e nevojshëm dhe kontrolloni përgjigjen në vend që të supozoni.
Ky pikëndalim nuk pranon id të organizatës. Çelësi juaj tashmë identifikon organizatën së cilës i përket dhe përgjigjja kufizohet vetëm për atë.
Provoje
Zëvendësoni çdo gjë brenda kllapave këndore me vlerat tuaja dhe vendbanuesin e çelësit me një çelës nga paneli juaj.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/security \
-H "Authorization: Bearer zdk_live_…"Jeni kyçur? Konsola e API-së në panelin tuaj plotëson ID-në tuaj reale të organizatës dhe çelësin tuaj, dhe ekzekuton kërkesën kundrejt API-së live, kështu që ju mund të shihni përgjigjen aktuale. Hapni këtë pikë fundore në konsolën e API-së
Detajet
The per-site Tools tab's *Malware and security* card — the scan verdict, when it last completed, and every live finding. RLS-scoped to a site the caller can view (`sites.view`); an out-of-scope or unknown id is a `404`, exactly like `getSite`. **This reads a stored projection and never calls the scanner.** The card mounts with the Tools tab for every site and polls while a scan is in flight, so a vendor round-trip here would be an un-cached external call in a hot path (CLAUDE.md §2.16). A scan is a durable Temporal workflow (§2.9) that writes the row this returns. `status: clean` with `last_scan_at: null` means **not scanned yet** — one nullable timestamp rather than a fourth status. "We could not look" is deliberately distinguishable from "we looked and it is fine", because neither a failed nor an un-attempted scan stamps `last_scan_at`. ⛔ **"We tried and could not" and "we have never tried" are different facts and arrive in different fields.** `last_scan_error` carries the first (an attempt ran and broke — an unreachable host, a vendor error, a scan abandoned after timing out); `unavailable_reason` carries the second as a machine identifier (nothing is attached to scan this site, or its platform cannot be scanned at all). They are never both non-empty. Render the first as a warning and the second as a neutral notice: showing *"we couldn't scan this site"* over a scan that was never attempted tells a customer their site might be infected when nothing of the sort is known. `detections[].path` is always **relative to the document root** — an absolute path would disclose the host account handle and the fleet's filesystem layout (§2.4).
Parametrat
| Emri | Lloji | Kërkohet | Çfarë është kjo |
|---|---|---|---|
siteId (path) | Uuid | Po | Site ID (UUIDv7). |
Përgjigja
| Emri | Lloji | Kërkohet | Çfarë është kjo |
|---|---|---|---|
status | MalwareStatus | Po | A site's scan verdict. There is deliberately **no** `unscanned` member: a site nothing has looked at yet is `clean` with `last_scan_at: null`, which is one nullable timestamp ra… |
last_scan_at | object | Po | When a scan last **completed**. `null` = never scanned. A scan that failed does not stamp this, so a stale success can never be mistaken for a fresh one. |
detections | MalwareDetection[] | Po | — |
recent_resolutions | ResolvedMalwareDetection[] | Po | Findings that were present and are not any more, most recently cleared first — the record of the protection having worked, which an all-clear alone cannot show. `resolved_at` al… |
can_rescan | boolean | Po | Whether `rescanSite` will accept a request for this site: false while a scan is already running, false for a site that is not running at all (there is no document root to scan),… |
last_scan_error_code | string<, scan_conflict, scanner_unreachable, scanner_missing, scan_failed> | Po | Why a scan that **ran** could not finish; empty when none has failed. Non-empty means an attempt was made against this site and broke — an unreachable host, a vendor error, a sc… |
unavailable_reason | string | Po | Why **no scan was attempted**; empty when one was. A stable machine identifier for the client to localise, never a sentence and never a vendor name. `vendor_unsupported` — the h… |
runtime | SiteRuntimeSecurity | Po | What our runtime sensor saw **happen** on this site, and whether anything was watching it at all. The malware fields above are a verdict on files at rest; this is the other half… |
Gabimet që ky pikëndalim mund të kthejë
401 · 403 · 404 · 429