身份验证
请将 API 密钥作为 bearer 令牌发送。该密钥必须具有 sites.view 权限;缺少该权限的密钥将被拒绝并返回 403 状态码,而非 404。
此端点不需要组织 ID。您的密钥已用于识别其所属的组织,且响应范围也仅限于该组织。
免费试用
将尖括号中的内容替换为您自己的值,并将键占位符替换为您仪表板中的一个键。
curl -X PUT https://api.zinndigital.com/v1/sites/{siteId}/protection/countries \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "countries": <string[]> }'已登录?您仪表板中的 API 控制台会自动填入您真实的组织 ID 和您自己的密钥,并针对实时 API 运行请求,以便您查看实际的响应。 在 API 控制台中打开此端点
详细信息
A **replace, not a patch**: the platform's endpoint replaces the list, and an empty list is its documented way to clear every country restriction — so *"unblock everywhere"* needs no second verb. ⛔ `allow_only` inverts who can reach the customer's site: `false` blocks the listed countries, `true` blocks everyone **except** them. It is its own boolean rather than a mode string precisely because a free-form word invites each consumer to re-derive that, and getting it backwards takes the site off the internet for everybody. A value that is not a two-letter country code is refused `422` before the vendor is called, with our sentence. `404` for a site with no vendor hosting package. Requires `sites.view` and `sites.panel_access`.
参数
| 名称 | 类型 | 必填 | 内容简介 |
|---|---|---|---|
siteId (path) | Uuid | 是 | Site ID (UUIDv7). |
请求正文
| 名称 | 类型 | 必填 | 内容简介 |
|---|---|---|---|
countries | string[] | 是 | The whole rule, as two-letter ISO 3166-1 alpha-2 codes. An empty array clears the restriction entirely. |
allow_only | boolean | 否 | `false` blocks the listed countries. `true` makes the list an **allow**-list — only those countries reach the site, and everyone else is blocked. |
响应
| 名称 | 类型 | 必填 | 内容简介 |
|---|---|---|---|
countries | string[] | 是 | The countries in the rule, as ISO 3166-1 alpha-2 codes. |
countries_allow_only | boolean | 是 | ⛔ `true` means `countries` is an **allow**-list: only those countries reach the site. Its own field rather than a mode string, because inverting it inverts who can reach the cus… |
blocked_addresses | string[] | 是 | The blocked addresses and CIDR ranges, canonicalised — what is here is what is in force, not what was typed. |
visitor_blocking_permitted | boolean | 是 | Whether the package type permits blocking visitors at all. One flag governs both lists. |
hotlink_configured | boolean | 是 | Whether any hotlink rule exists. ⛔ `false` means *no rules have been set up* — **not** "protection is on with no allowed hosts", which would read as a site blocking everybody. |
hotlink_allow_direct | boolean | 是 | Whether a request with no referrer is allowed through. **Null** when the vendor did not state it — distinct from `false`, because a toggle rendered from an unknown lies about th… |
hotlink_allowed_hostnames | string[] | 是 | The sites permitted to embed these files. |
hotlink_redirect_url | string | 是 | Where a refused request is sent instead, or `""` when it is simply refused. |
hotlink_extensions | string[] | 是 | The file extensions the rule covers, normalised without a leading dot. |
hotlink_permitted | boolean | 是 | Whether the package type includes hotlink protection. |
directories | SiteProtectedDirectory[] | 是 | The password-protected folders. ⛔ Read from a vendor field that documents `null` as *"the request could not complete"* — the opposite of "nothing is protected" — so an unreadabl… |
password_protection_permitted | boolean | 是 | Whether the package type includes password-protected directories. |
malware_scan_permitted | boolean | 是 | Whether the package type includes the vendor's malware scan — the capability behind `scanSite` on this deploy target. |
此端点可能返回的错误
401 · 403 · 404 · 409 · 422 · 429 · 503