hosting

POST /v1/sites/{siteId}/backups/{backupId}/download

Mint a time-limited download URL for one of a site's backups.

Све hosting крајње тачке

Сва документација за програмере →

Аутентификација

Пошаљите API кључ као bearer токен. Кључ мора имати дозволу hosting.backup.export; кључ без ње се одбија уз 403, а не 404.

Ова крајња тачка не прихвата id организације. Ваш кључ већ идентификује организацију којој припада, а одговор је ограничен на њу.

Испробајте

Замените све што је у угластим заградама сопственим вредностима, а чувар места кључа кључем са своје контролне табле.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/backups/{backupId}/download \
  -H "Authorization: Bearer zdk_live_…"

Пријављени сте? API конзола на вашој контролној табли попуњава ваш прави id организације и ваш сопствени кључ, и покреће захтев према живом API-ју како бисте могли да видите стварни одговор. Отворите ову крајњу тачку у API конзоли

Детаљи

Returns a presigned URL the customer's browser fetches directly from object storage; the archive never passes through the control plane. A site archive is measured in gigabytes, so proxying it would make the customer's site size our memory ceiling and hold a request thread for the length of the transfer. ⛔ POST, despite reading nothing. The response body is a bearer credential for the whole site — database included — so a GET would invite it into browser history, proxy logs and shared caches, and the audit row this writes would be created by every prefetch. The grant expires; take a new one rather than storing it. A backup that never produced a stored archive is 422 (backup_not_downloadable) rather than a signature over a key that is not there, which object storage would reject seconds later as an opaque 404. Requires hosting.backup.export — or hosting.backup.manage, which every holder of the old gate still has — and never sites.view: reading a tenant's database out is never a viewer's. A per-site editor holds hosting.backup.export, which is how zinnector pull brings the site down for local development — files and database — without being able to restore. The site.backup.exported audit row records has_database (three states; null is not recorded, never no) and whether the caller holds the site through a per-site grant, so a site's owner can answer "did the developer I shared this with take my database?" from their own audit log rather than by asking.

Параметри

НазивТипОбавезноШта је ово
siteId (path)UuidДаSite ID (UUIDv7).
backupId (path)UuidДаThe backup's id (UUIDv7), as getSiteBackups reports it. Ours, minted when the row was written — never the storage key, which is an internal object path and is deliberately…

Одговор

НазивТипОбавезноШта је ово
urlstringДаThe presigned object-storage URL to fetch the archive from. Hand it straight to the customer's browser and let it expire; take a fresh grant rather than caching this one.
expires_atstringДаWhen the signature stops working. A download that has already started is unaffected; a new one after this moment is refused by storage.
size_bytesintegerДаThe archive's size, as object storage reported it when the backup was stored — so a client can warn before a multi-gigabyte download.
etagstringДаThe stored object's entity tag, for a client that wants to verify the bytes it received are the bytes we hold. Empty when the backend did not report one.

Грешке које ова крајња тачка може вратити

401 · 403 · 404 · 422 · 429