Skip to main content

Create Access Control V2

This API is used to configure access control for the website acceleration service.

Request

Request-Line

POST /cdn/v1.1/services/{serviceId}/accessControl HTTP/1.1

Request Parameters

Path Parameters

ParameterTypeRequiredDescription
serviceIdIntegerMandatoryThe unique identifier of the website acceleration service.

Body Parameters

ParameterTypeRequiredDescription
policyNameStringMandatoryPolicy name for access control.
typeStringMandatoryAccess control type. Must be allow, deny or token.
matchesArrayMandatoryMatching configuration that determines which requests the rule applies to. See Matches for details.
priorityIntegerOptionalPriority weight for the rule. Rules with a higher weight take precedence. The weight must be a positive integer.
ipRestrictionStringOptionalThe value must be a comma-separated list of IPs or CIDR networks. Only requests from these subnets are allowed. All other requests will be rejected with a 403 Forbidden response.
geoRestrictionStringOptionalThe value must be a comma-separated list of geographic locations. Each location must be specified as a 2-letter ISO 3166 code (e.g., CN, GB).
anonymousIpBooleanOptionalWhen true, the rule applies to requests from anonymous IPs (e.g., VPNs, proxies). When false, it applies to non-anonymous IPs only, Default is false.
tokenSecretStringOptionalThe tokenSecret Field is applicable only when type is token. The value must be a comma-separated list of tokens. Each token must be exactly 64 characters long, and each character must be a digit (0-9) or a lowercase letter (a-z).
enabledBooleanOptionalFlag indicating whether the rule is active. Default is true.
Object: Matches
ParameterTypeRequiredDescription
ArrayMandatorySee Match for details.
Object: Match
ParameterTypeRequiredDescription
fieldStringMandatoryWhich part of the request to match. Supported values:
req.path - Request path (excluding query string).
req.query - Request query parameters.
req.method - HTTP method (e.g., GET or POST).
client.ip - Client IP address.
req.host - Request host.
req.header.user-agent - User-Agent header.
req.header.cookie - Cookie header.
req.header.origin - Origin header.
req.header.via - Via header.
operatorStringMandatoryDefines how to match the field. Supported values:
startswith - Succeeds if the what matches one of the prefixes listed in patterns.
not_startswith - Matches if field value does not starts with any of the specified prefixes.
istartswith - Case-independent version of startswith.
not_istartwith - Matches if the field value does not starts with any of the specified prefixes, ignoring letter case differences.
regex - Succeeds if what matches one of the regexes listed in patterns.
equals - Succeeds if the what matches one of the strings listed in patterns.
not_equals - Succeeds if the field value does not exactly match any of the specified strings.
iequals - Case-independent version of equals.
not_iequals - Succeeds if the field value does not exactly match any of the specified strings, ignoring letter case differences.
endswith - Succeeds if the what ends with one of the strings listed in patterns. Useful e.g. to match file extensions like ".mp4".
not_endswith - Succeeds if the what does not ends with one of the strings listed in patterns.
iendswith - Case-independent version of endswith.
not_iendswith - Succeeds if the what does not ends with one of the strings listed in patterns, ignoring letter case differences.
subnet - Succeeds if the what belongs to one of subnets, specified in patterns, like "1.222.94.98/32".
not_subnet - Succeeds if the what does not belongs to one of subnets.
Note: subnet operator is applicable only to the client.ip match option.
valuesArrayMandatoryList of values matching the URL path string.

Response

Response Body

ParameterTypeDescription
policyIdIntegerPolicy ID number for access control.
policyNameStringPolicy name for access control.
typeStringAccess control type can be allow, deny, or token.
matchesArrayMatching configuration that determines which requests the rule applies to. See Matches for details.
priorityIntegerPriority weight for the rule. Rules with a higher weight take precedence. The weight must be a positive integer.
ipRestrictionStringThe value must be a comma-separated list of IPs or CIDR networks. Only requests from these subnets are allowed. All other requests will be rejected with a 403 Forbidden response.
geoRestrictionStringThe value must be a comma-separated list of geographic locations. Each location must be specified as a 2-letter ISO 3166 code (e.g., CN, GB).
anonymousIpBooleanWhen true, the rule applies to requests from anonymous IPs (e.g., VPNs, proxies). When false, it applies to non-anonymous IPs only, Default is false.
tokenSecretStringThe tokenSecret Field is applicable only when type is token. The value must be a comma-separated list of tokens. Each token must be exactly 64 characters long, and each character must be a digit (0-9) or a lowercase letter (a-z).
enabledBooleanFlag indicating whether the rule is active. Default is true.

Status Codes, Error Codes and Error Messages

Status CodeError CodeError Message
400Request.BadRequestBad request.
400InvalidCustomer.IdEmptyCustomer ID cannot empty or invalid.
400InvalidService.IdIncorrectService ID is empty or invalid.
400InvalidService.IdPermissionService ID cannot be found or unknown.
400Invalid.PolicyNamePolicy name is required.
400InvalidPolicy.TypeEmptyPolicy type cannot be empty.
400InvalidPolicy.AccessTypePolicy access type must be one of the following values: allow, deny, or token.
400InvalidPolicy.MatchURLIncorrectThe matchUrlPath cannot be empty.
400InvalidPolicy.OperatorOperator must be one of the following values: prefix, regex, equals, or suffix.
400InvalidPolicy.MatchUrlPathPatternsIncorrectThe MatchUrlPath patterns cannot be empty.
400InvalidPolicy.PriorityPriority is required.
400InvalidPolicy.IpRestrictionIP restriction format is incorrect. Supported formats: 172.31.31.0, 172.31.31.0/255.255.255.0, or 172.31.32.0/24.
400InvalidPolicy.GeoFormatGeo restriction format is incorrect.
400InvalidPolicy.MatchesIncorrectThe matches cannot be empty or incorrect.
400InvalidPolicy.MatchFieldIncorrectThe match field cannot be empty and must be one of the supported values.
400InvalidPolicy.MatchOperatorIncorrectThe match operator cannot be empty and must be one of the supported values.
400InvalidPolicy.MatchValuesIncorrectThe match values are required and cannot be empty.
400InvalidPolicy.MatchValueIncorrectAll match values cannot be empty.

Examples

Create Access Control V2

Request

POST /cdn/v1.1/services/229033/accessControl HTTP/1.1

{
"policyName":"access",
"matches":[
{
"field":"req.path",
"operator":"startswith",
"values":["/css/","/images/abc/"]
},
{
"field":"req.host",
"operator":"iequals",
"values":["example.com"]
},
{
"field":"req.method",
"operator":"equals",
"values":["get"]
}
],
"priority":37,
"type":"allow",
"geoRestriction":"US,CN",
"ipRestriction":"172.16.12.1",
"anonymousIp":true,
"tokenSecret":"bdfy7r6jflo3iydy9zxigkl5m0hte6d423d45dfg6gavo07xvmtc4tzsdc9yxyjy",
"enabled":true
}

Successful Response Body

{
"policyId": 262273,
"policyName": "access",
"type": "allow",
"matches":[
{
"field":"req.path",
"operator":"startswith",
"values":["/css/","/images/abc/"]
},
{
"field":"req.host",
"operator":"iequals",
"values":["example.com"]
},
{
"field":"req.method",
"operator":"equals",
"values":["get"]
}
],
"priority": 37,
"ipRestriction": "172.16.12.1",
"geoRestriction": "CN,US",
"anonymousIp": true,
"tokenSecret": "bdfy7r6jflo3iydy9zxigkl5m0hte6d423d45dfg6gavo07xvmtc4tzsdc9yxyjy",
"enabled": true
}