文档目录

IP黑白名单相关接口

增加IP访问控制规则(AddAccessControlRule)

API请求

URLs
POST zstack/v1/login-control/access-control/rules
Headers
Authorization: OAuth the-session-uuid
Body
{
  "params": {
    "name": "rule1",
    "description": "this is a rule",
    "rule": "172.20.1.1,172.20.1.2",
    "controlStrategy": "ACCEPT"
  },
  "systemTags": [],
  "userTags": []
}
Note: 上述示例中systemTagsuserTags字段可以省略。列出是为了表示body中可以包含这两个字段。
Curl示例
curl -H "Content-Type: application/json;charset=UTF-8" \
-H "Authorization: OAuth b86c9016b4f24953a9edefb53ca0678c" \
-X POST -d '{"params":{"name":"rule1","description":"this is a rule","rule":"172.20.1.1,172.20.1.2","controlStrategy":"ACCEPT"}}' http://localhost:8080/zstack/v1/login-control/access-control/rules
参数列表
名字 类型 位置 描述 可选值 起始版本
name String body(包含在params结构中) 资源名称 3.5.1
description (可选) String body(包含在params结构中) 资源的详细描述 3.5.1
rule String body(包含在params结构中) 3.5.1
controlStrategy String body(包含在params结构中) 3.5.1
resourceUuid (可选) String body(包含在params结构中) 3.5.1
tagUuids (可选) List body(包含在params结构中) 标签UUID列表 3.5.1
systemTags (可选) List body 3.5.1
userTags (可选) List body 3.5.1

API返回

该API成功时返回一个空的JSON结构{},出错时返回的JSON结构包含一个error字段,例如:
{
	"error": {
		"code": "SYS.1001",
		"description": "A message or a operation timeout",
		"details": "Create VM on KVM timeout after 300s"
	}
}

SDK示例

Java SDK
AddAccessControlRuleAction action = new AddAccessControlRuleAction();
action.name = "rule1";
action.description = "this is a rule";
action.rule = "172.20.1.1,172.20.1.2";
action.controlStrategy = "ACCEPT";
action.sessionId = "b86c9016b4f24953a9edefb53ca0678c";
AddAccessControlRuleAction.Result res = action.call();
Python SDK
AddAccessControlRuleAction action = AddAccessControlRuleAction()
action.name = "rule1"
action.description = "this is a rule"
action.rule = "172.20.1.1,172.20.1.2"
action.controlStrategy = "ACCEPT"
action.sessionId = "b86c9016b4f24953a9edefb53ca0678c"
AddAccessControlRuleAction.Result res = action.call()

删除IP访问控制规则(DeleteAccessControlRule)

API请求

URLs
DELETE zstack/v1/login-control/access-control/rules/{uuid}
Headers
Authorization: OAuth the-session-uuid
Curl示例
curl -H "Content-Type: application/json;charset=UTF-8" \
-H "Authorization: OAuth b86c9016b4f24953a9edefb53ca0678c" \
-X DELETE http://localhost:8080/zstack/v1/login-control/access-control/rules/04baa07ba917360394ec649e26b93593?
参数列表
名字 类型 位置 描述 可选值 起始版本
uuid String url 资源的UUID,唯一标示该资源 3.5.1
deleteMode (可选) String body 3.5.1
systemTags (可选) List body 3.5.1
userTags (可选) List body 3.5.1

API返回

该API成功时返回一个空的JSON结构{},出错时返回的JSON结构包含一个error字段,例如:
{
	"error": {
		"code": "SYS.1001",
		"description": "A message or a operation timeout",
		"details": "Create VM on KVM timeout after 300s"
	}
}

SDK示例

Java SDK
DeleteAccessControlRuleAction action = new DeleteAccessControlRuleAction();
action.uuid = "04baa07ba917360394ec649e26b93593";
action.deleteMode = "Permissive";
action.sessionId = "b86c9016b4f24953a9edefb53ca0678c";
DeleteAccessControlRuleAction.Result res = action.call();
Python SDK
DeleteAccessControlRuleAction action = DeleteAccessControlRuleAction()
action.uuid = "04baa07ba917360394ec649e26b93593"
action.deleteMode = "Permissive"
action.sessionId = "b86c9016b4f24953a9edefb53ca0678c"
DeleteAccessControlRuleAction.Result res = action.call()

更新IP访问控制规则(UpdateAccessControlRule)

API请求

URLs
PUT zstack/v1/login-control/access-control/rules/{uuid}/actions
Headers
Authorization: OAuth the-session-uuid
Body
{
  "updateAccessControlRule": {
    "name": "rule1",
    "description": "this is a rule"
  },
  "systemTags": [],
  "userTags": []
}
Note: 上述示例中systemTagsuserTags字段可以省略。列出是为了表示body中可以包含这两个字段。
Curl示例
curl -H "Content-Type: application/json;charset=UTF-8" \
-H "Authorization: OAuth b86c9016b4f24953a9edefb53ca0678c" \
-X PUT -d '{"updateAccessControlRule":{"name":"rule1","description":"this is a rule"}}' http://localhost:8080/zstack/v1/login-control/access-control/rules/6bc3181222854438ac8af53f2b57ecf7/actions
参数列表
名字 类型 位置 描述 可选值 起始版本
uuid String url 资源的UUID,唯一标示该资源 3.5.1
name (可选) String body(包含在updateAccessControlRule结构中) 资源名称 3.5.1
description (可选) String body(包含在updateAccessControlRule结构中) 资源的详细描述 3.5.1
systemTags (可选) List body 3.5.1
userTags (可选) List body 3.5.1

API返回

返回示例
{
  "inventory": {
    "name": "rule",
    "description": "this is rule description",
    "rule": "172.20.1.1",
    "strategy": "ACCEPT",
    "createDate": "Nov 14, 2017 10:20:57 PM",
    "lastOpDate": "Nov 14, 2017 10:20:57 PM"
  }
}
名字 类型 描述 起始版本
error ErrorCode 错误码,若不为null,则表示操作失败, 操作成功时该字段为null。 详情参考error 3.5.1
inventory AccessControlRuleInventory 详情参考inventory 3.5.1
#error
名字 类型 描述 起始版本
code String 错误码号,错误的全局唯一标识,例如SYS.1000, HOST.1001 3.5.1
description String 错误的概要描述 3.5.1
details String 错误的详细信息 3.5.1
elaboration String 保留字段,默认为null 3.5.1
opaque LinkedHashMap 保留字段,默认为null 3.5.1
cause ErrorCode 根错误,引发当前错误的源错误,若无原错误,该字段为null 3.5.1
#inventory
名字 类型 描述 起始版本
uuid String 资源的UUID,唯一标示该资源 3.5.1
name String 资源名称 3.5.1
description String 资源的详细描述 3.5.1
rule String 3.5.1
createDate Timestamp 创建时间 3.5.1
lastOpDate Timestamp 最后一次修改时间 3.5.1
strategy ControlStrategy 详情参考strategy 3.5.1
#strategy
名字 类型 描述 起始版本
ACCEPT ControlStrategy 3.5.1
REJECT ControlStrategy 3.5.1

SDK示例

Java SDK
UpdateAccessControlRuleAction action = new UpdateAccessControlRuleAction();
action.uuid = "c3fb6843d7b84791bbffb762e35b3065";
action.name = "rule1";
action.description = "this is a rule";
action.sessionId = "b86c9016b4f24953a9edefb53ca0678c";
UpdateAccessControlRuleAction.Result res = action.call();
Python SDK
UpdateAccessControlRuleAction action = UpdateAccessControlRuleAction()
action.uuid = "4c30b1ea5adf450ebca75f8b8606b964"
action.name = "rule1"
action.description = "this is a rule"
action.sessionId = "b86c9016b4f24953a9edefb53ca0678c"
UpdateAccessControlRuleAction.Result res = action.call()

查询IP访问控制规则(QueryAccessControlRule)

API请求

URLs
GET zstack/v1/login-control/access-control/rules
Headers
Authorization: OAuth the-session-uuid
Curl示例
curl -H "Content-Type: application/json;charset=UTF-8" \
-H "Authorization: OAuth b86c9016b4f24953a9edefb53ca0678c" \
-X GET http://localhost:8080/zstack/v1/login-control/access-control/rules?q=uuid=4f41ad1c52ac3ba690282ede3d1ebb2a

可查询字段

运行CLI命令行工具,输入QueryAccessControlRule并按Tab键查看所有可查询字段以及可跨表查询的资源名。

API返回

返回示例
{
  "inventories": [
    {
      "rule": "192.168.10.0/24"
    }
  ]
}
名字 类型 描述 起始版本
error ErrorCode 错误码,若不为null,则表示操作失败, 操作成功时该字段为null。 详情参考error 3.5.1
inventories List 详情参考inventories 3.5.1
#error
名字 类型 描述 起始版本
code String 错误码号,错误的全局唯一标识,例如SYS.1000, HOST.1001 3.5.1
description String 错误的概要描述 3.5.1
details String 错误的详细信息 3.5.1
elaboration String 保留字段,默认为null 3.5.1
opaque LinkedHashMap 保留字段,默认为null 3.5.1
cause ErrorCode 根错误,引发当前错误的源错误,若无原错误,该字段为null 3.5.1
#inventories
名字 类型 描述 起始版本
uuid String 资源的UUID,唯一标示该资源 3.5.1
name String 资源名称 3.5.1
description String 资源的详细描述 3.5.1
rule String 3.5.1
createDate Timestamp 创建时间 3.5.1
lastOpDate Timestamp 最后一次修改时间 3.5.1
strategy ControlStrategy 详情参考strategy 3.5.1
#strategy
名字 类型 描述 起始版本
ACCEPT ControlStrategy 3.5.1
REJECT ControlStrategy 3.5.1

SDK示例

Java SDK
QueryAccessControlRuleAction action = new QueryAccessControlRuleAction();
action.conditions = asList("uuid=b4cae0f6a9ac3cd686ba36c81291d197");
action.sessionId = "b86c9016b4f24953a9edefb53ca0678c";
QueryAccessControlRuleAction.Result res = action.call();
Python SDK
QueryAccessControlRuleAction action = QueryAccessControlRuleAction()
action.conditions = ["uuid=4b3f7d2f1fda3f1d8089b4d037364bf9"]
action.sessionId = "b86c9016b4f24953a9edefb53ca0678c"
QueryAccessControlRuleAction.Result res = action.call()

获取登录验证码(GetLoginCaptcha)

API请求

URLs
GET zstack/v1/login/control/captcha
Curl示例
curl -H "Content-Type: application/json;charset=UTF-8" -X GET http://localhost:8080/zstack/v1/login/control/captcha?resourceName=admin&loginType=Test
参数列表
名字 类型 位置 描述 可选值 起始版本
resourceName String query 3.5.1
loginType String query 3.5.1
captchaUuid (可选) String query 3.5.1
systemTags (可选) List query 3.5.1
userTags (可选) List query 3.5.1

API返回

返回示例
{
  "captchaUuid": "64dd651f9c0043c28490b3a4d76d394e",
  "captcha": "test"
}
名字 类型 描述 起始版本
captchaUuid String 3.5.1
captcha String 3.5.1
success boolean 3.5.1
error ErrorCode 错误码,若不为null,则表示操作失败, 操作成功时该字段为null。 详情参考error 3.5.1
error ErrorCode 详情参考error 3.5.1
#error
名字 类型 描述 起始版本
code String 错误码号,错误的全局唯一标识,例如SYS.1000, HOST.1001 3.5.1
description String 错误的概要描述 3.5.1
details String 错误的详细信息 3.5.1
elaboration String 保留字段,默认为null 3.5.1
opaque LinkedHashMap 保留字段,默认为null 3.5.1
cause ErrorCode 根错误,引发当前错误的源错误,若无原错误,该字段为null 3.5.1
#error
名字 类型 描述 起始版本
code String 错误码号,错误的全局唯一标识,例如SYS.1000, HOST.1001 3.5.1
description String 错误的概要描述 3.5.1
details String 错误的详细信息 3.5.1
elaboration String 保留字段,默认为null 3.5.1
opaque LinkedHashMap 保留字段,默认为null 3.5.1
cause ErrorCode 根错误,引发当前错误的源错误,若无原错误,该字段为null 3.5.1

SDK示例

Java SDK
GetLoginCaptchaAction action = new GetLoginCaptchaAction();
action.resourceName = "admin";
action.loginType = "Test";
GetLoginCaptchaAction.Result res = action.call();
Python SDK
GetLoginCaptchaAction action = GetLoginCaptchaAction()
action.resourceName = "admin"
action.loginType = "Test"
GetLoginCaptchaAction.Result res = action.call()
开发手册 | 5.4.12 | ZStack Cloud · ZCF | ZStack 资源中心