hosting
GET /v1/sites/{siteId}/security
A site's malware state and live findings.
Автентифікація
Надішліть ключ API як маркер носія (bearer token). Ця кінцева точка не вказує конкретного дозволу в специфікації, тому надайте своєму ключу мінімально необхідні права та перевірте відповідь, замість того щоб припускати.
Цей кінцевий пункт не потребує ідентифікатора організації. Ваш ключ уже ідентифікує організацію, якій він належить, і відповідь обмежується її межами.
Спробувати
Замініть усе в кутових дужках власними значеннями, а заповнювач ключа — ключем із вашої панелі керування.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/security \
-H "Authorization: Bearer zdk_live_…"Увійшли в систему? Консоль API у вашій панелі керування автоматично підставляє ваш реальний ідентифікатор організації та ваш власний ключ, а також виконує запит до робочого API, щоб ви могли побачити справжню відповідь. Відкрийте цю кінцеву точку в консолі API
Деталі
The per-site Tools tab's Malware and security card — the scan verdict, when it last completed, and every live finding. RLS-scoped to a site the caller can view (sites.view); an out-of-scope or unknown id is a 404, exactly like getSite. This reads a stored projection and never calls the scanner. The card mounts with the Tools tab for every site and polls while a scan is in flight, so a vendor round-trip here would be an un-cached external call in a hot path (CLAUDE.md §2.16). A scan is a durable Temporal workflow (§2.9) that writes the row this returns. status: clean with last_scan_at: null means not scanned yet — one nullable timestamp rather than a fourth status. "We could not look" is deliberately distinguishable from "we looked and it is fine", because neither a failed nor an un-attempted scan stamps last_scan_at. ⛔ "We tried and could not" and "we have never tried" are different facts and arrive in different fields. last_scan_error carries the first (an attempt ran and broke — an unreachable host, a vendor error, a scan abandoned after timing out); unavailable_reason carries the second as a machine identifier (nothing is attached to scan this site, or its platform cannot be scanned at all). They are never both non-empty. Render the first as a warning and the second as a neutral notice: showing "we couldn't scan this site" over a scan that was never attempted tells a customer their site might be infected when nothing of the sort is known. detections[].path is always relative to the document root — an absolute path would disclose the host account handle and the fleet's filesystem layout (§2.4).
Параметри
| Назва | Тип | Обов'язкове | Що це таке |
|---|---|---|---|
siteId (path) | Uuid | Так | Site ID (UUIDv7). |
Відповідь
| Назва | Тип | Обов'язкове | Що це таке |
|---|---|---|---|
status | MalwareStatus | Так | A site's scan verdict. There is deliberately no unscanned member: a site nothing has looked at yet is clean with last_scan_at: null, which is one nullable timestamp… |
last_scan_at | object | Так | When a scan last completed. null = never scanned. A scan that failed does not stamp this, so a stale success can never be mistaken for a fresh one. |
detections | MalwareDetection[] | Так | — |
recent_resolutions | ResolvedMalwareDetection[] | Так | Findings that were present and are not any more, most recently cleared first — the record of the protection having worked, which an all-clear alone cannot show. resolved_at… |
can_rescan | boolean | Так | Whether rescanSite will accept a request for this site: false while a scan is already running, false for a site that is not running at all (there is no document root to scan),… |
last_scan_error_code | string<, scan_conflict, scanner_unreachable, scanner_missing, scan_failed> | Так | Why a scan that ran could not finish; empty when none has failed. Non-empty means an attempt was made against this site and broke — an unreachable host, a vendor error, a scan… |
unavailable_reason | string | Так | Why no scan was attempted; empty when one was. A stable machine identifier for the client to localise, never a sentence and never a vendor name. vendor_unsupported — the… |
runtime | SiteRuntimeSecurity | Так | What our runtime sensor saw happen on this site, and whether anything was watching it at all. The malware fields above are a verdict on files at rest; this is the other half —… |
Помилки, які може повертати ця кінцева точка
401 · 403 · 404 · 429