hosting
POST /v1/sites/{siteId}/backups/{backupId}/download
Mint a time-limited download URL for one of a site's backups.
Санҷиши ҳаққоният
Kaliti API-ро ҳамчун рамзи доранда (bearer token) фиристед. Калит бояд дорои иҷозати hosting.backup.export бошад; калиди бидуни он бо хатои 403 рад карда мешавад, на 404.
Ин нуқтаи поёнӣ ягон рақами мушаххаси созмонро талаб намекунад. Калиди шумо аллакай созмонеро, ки ба он тааллуқ дорад, муайян мекунад ва ҷавоб ба он маҳдуд карда мешавад.
Санҷидан
Ҳар чизро дар қаavски кунҷӣ бо қиматҳои худ ва ҷойи нигоҳдорандаи калидро бо калима аз панели идоракунии худ иваз кунед.
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/backups/{backupId}/download \
-H "Authorization: Bearer zdk_live_…"Воarid шудаед? Консоли API дар панели идоракунии шумо рақами мушаххаси ташкилоти воқеӣ ва калиди худро пур мекунад ва дархостро бар зидди API-и фаъол иҷро мекунад, то шумо посухи воқеиро бубинед. Ин нуқтаи ниҳоиро дар консоли API кушоед
Тафсилот
Returns a presigned URL the customer's browser fetches **directly from object storage**; the archive never passes through the control plane. A site archive is measured in gigabytes, so proxying it would make the customer's site size our memory ceiling and hold a request thread for the length of the transfer. ⛔ **`POST`, despite reading nothing.** The response body is a bearer credential for the whole site — database included — so a `GET` would invite it into browser history, proxy logs and shared caches, and the audit row this writes would be created by every prefetch. The grant expires; take a new one rather than storing it. A backup that never produced a stored archive is `422` (`backup_not_downloadable`) rather than a signature over a key that is not there, which object storage would reject seconds later as an opaque `404`. Requires `hosting.backup.export` — or `hosting.backup.manage`, which every holder of the old gate still has — and never `sites.view`: reading a tenant's database out is never a viewer's. A per-site *editor* holds `hosting.backup.export`, which is how `zinnector pull` brings the files down for local development without being able to restore.
Параметрҳо
| Ном | Намуд | Талаб карда мешавад | Ин чӣ аст |
|---|---|---|---|
siteId (path) | Uuid | Бале | Site ID (UUIDv7). |
backupId (path) | Uuid | Бале | The backup's id (UUIDv7), as `getSiteBackups` reports it. **Ours**, minted when the row was written — never the storage key, which is an internal object path and is deliberately… |
Ҷавоб
| Ном | Намуд | Талаб карда мешавад | Ин чӣ аст |
|---|---|---|---|
url | string | Бале | The presigned object-storage URL to fetch the archive from. Hand it straight to the customer's browser and let it expire; take a fresh grant rather than caching this one. |
expires_at | string | Бале | When the signature stops working. A download that has already started is unaffected; a new one after this moment is refused by storage. |
size_bytes | integer | Бале | The archive's size, as object storage reported it when the backup was stored — so a client can warn before a multi-gigabyte download. |
etag | string | Бале | The stored object's entity tag, for a client that wants to verify the bytes it received are the bytes we hold. Empty when the backend did not report one. |
Хатоҳое, ки ин нуқтаи ниҳоӣ метавонад баргардонад
401 · 403 · 404 · 422 · 429