hosting
POST /v1/sites/{siteId}/wordpress/cli
Run one allow-listed WP-CLI command on the site.
Xác thực
Gửi khóa API dưới dạng mã thông báo bearer. Khóa này phải có quyền sites.view; khóa không có quyền này sẽ bị từ chối với mã lỗi 403, không phải 404.
Endpoint này không nhận ID tổ chức. Khóa của bạn đã xác định tổ chức mà nó thuộc về và phản hồi được giới hạn trong phạm vi đó.
Dùng thử
Thay thế bất kỳ nội dung nào trong ngoعل (angle brackets) bằng giá trị của riêng bạn và trình giữ chỗ key bằng một key từ trang tổng quan của bạn.
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/wordpress/cli \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "command": <string> }'Đã đăng nhập? Bảng điều khiển API trong trang quản lý của bạn sẽ tự điền ID tổ chức thực tế và khóa của riêng bạn, sau đó chạy yêu cầu đối với API trực tiếp để bạn có thể xem phản hồi thực tế. Mở điểm cuối này trong bảng điều khiển API
Chi tiết
An audited WP-CLI console. Every invocation is recorded in the site's WordPress activity log with its argv and exit code — never its output. ⛔ **Allow-listed, never arbitrary.** An unrestricted passthrough is remote code execution as the site user: `wp eval` runs arbitrary PHP, `wp db query` runs arbitrary SQL, and `wp --require=/tmp/x.php` loads code the caller chose before WP-CLI decides what to do. The permitted commands are reads and idempotent cache operations, listed by `listWordPressCliCommands`; anything else answers `422` naming the whole list. ⛔ `config get` and `config list` are **deliberately absent** — they read `wp-config.php`, whose constants include the database password and the authentication salts. ⛔ A **non-zero `exit_code` still answers `200`.** The console's product is what WP-CLI said, and mapping a bad argument onto a 4xx would put our error page over the diagnosis the customer asked for. A `422` means *we* refused the command, which is a different answer. ⛔ The command travels in the **body**, not the path, so it never reaches a proxy or edge access log — `option get` names options a plugin may have stored a credential in. ⛔ **Fleet only** — refused where `wp_cli` is `false`. Requires `sites.view` and `sites.panel_access`.
Tham số
| Tên | Loại | Bắt buộc | Nội dung này là gì |
|---|---|---|---|
siteId (path) | Uuid | Có | Site ID (UUIDv7). |
Nội dung yêu cầu
| Tên | Loại | Bắt buộc | Nội dung này là gì |
|---|---|---|---|
command | string | Có | The WP-CLI command, with or without a leading `wp`. |
Phản hồi
| Tên | Loại | Bắt buộc | Nội dung này là gì |
|---|---|---|---|
argv | string[] | Có | What actually ran, after the allow-list normalised it — echoed back so `wp plugin list` and `plugin list` are visibly the same command. |
exit_code | integer | Có | WP-CLI's exit code. `0` is success. |
stdout | string | Có | What WP-CLI printed, up to the console's cap. |
stderr | string | Có | WP-CLI's diagnostics, carried **separately** and never merged into `stdout` — WP-CLI writes PHP notices here on runs that succeed, so folding them together would corrupt the JSO… |
truncated | boolean | Có | True when `stdout` was cut at the cap. ⛔ Stated rather than hidden: a silently cut-off JSON document is worse than none, because it nearly parses. |
Các lỗi điểm cuối này có thể trả về
401 · 403 · 404 · 422 · 429 · 503