Edit Access Control
This API is used to edit access control for the website acceleration service.
Request
Request-Line
PUT /cdn/v1.0/services/{serviceId}/accessControl/{policyId} HTTP/1.1
Request Parameters
Path Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
| serviceId | Integer | Mandatory | The unique identifier of the website acceleration service. |
| policyId | Integer | Mandatory | Policy ID number for access control. |
Body Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
| policyName | String | Mandatory | Policy name for access control. |
| type | String | Mandatory | Access control type. Must be allow, deny, or token. |
| matchUrlPath | Object | Mandatory | URL path matching configuration that determines which requests the rule applies to. See Match Url Path for details. |
| priority | Integer | Optional | Priority weight for the rule. Rules with a higher weight take precedence. The weight must be a positive integer. |
| matchQueryString | Object | Optional | Query-string matching configuration used to refine which requests the rule applies to. See Match Query String for details. |
| ipRestriction | String | Optional | The value must be a comma-separated list of IPs or CIDR networks. Only requests from these subnets are allowed. All other requests will be rejected with a 403 Forbidden response. |
| geoRestriction | String | Optional | The value must be a comma-separated list of geographic locations. Each location must be specified as a 2-letter ISO 3166 code (e.g., CN, GB). |
| anonymousIp | Boolean | Optional | When true, the rule applies to requests from anonymous IPs (e.g., VPNs, proxies). When false, it applies to non-anonymous IPs only. Default is false. |
| tokenSecret | String | Optional | The tokenSecret field is required only when type is token. It is a comma-separated list of tokens. Each token must be exactly 64 characters long, and each character must be a digit (0-9) or a lowercase letter (a-z). |
| enabled | Boolean | Optional | Flag indicating whether the rule is active. Default is true. |
Object: Match Url Path
| Parameter | Type | Required | Description |
|---|---|---|---|
| operator | String | Mandatory | Defines how to match the field. Supported values: prefix, regex, equals, suffix. |
| patterns | Array | Mandatory | List of patterns matching the URL path string. |
Object: Match Query String
| Parameter | Type | Required | Description |
|---|---|---|---|
| operator | String | Mandatory | Defines how to match the field. Supported values: prefix, regex, equals, suffix. |
| patterns | Array | Mandatory | List of patterns matching the URL query string. |
Response
Response Body
| Parameter | Type | Description |
|---|---|---|
| policyId | Integer | Policy ID number for access control. |
| policyName | String | Policy name for access control. |
| type | String | Access control type. Can be allow, deny or token. |
| matchUrlPath | Object | URL path matching configuration that determines which requests the rule applies to. See Match Url Path for details. |
| priority | Integer | Priority weight for the rule. Rules with a higher weight take precedence. The weight must be non-zero. |
| matchQueryString | Object | Query-string matching configuration used to refine which requests the rule applies to. See Match Query String for details. |
| ipRestriction | String | The value must be a comma-separated list of IPs or CIDR networks. Only requests from these subnets are allowed. All other requests will be rejected with a 403 Forbidden response. |
| geoRestriction | String | The value must be a comma-separated list of geographic locations. Each location must be specified as a 2-letter ISO 3166 code (e.g., CN, GB). |
| anonymousIp | Boolean | When true, the rule applies to requests from anonymous IPs (e.g., VPNs, proxies). When false, it applies to non-anonymous IPs only. Default is false. |
| tokenSecret | String | The tokenSecret field is required only when type is token. It is a comma-separated list of tokens. Each token must be exactly 64 characters long, and each character must be a digit (0-9) or a lowercase letter (a-z). |
| enabled | Boolean | Flag indicating whether the rule is active. Default is true. |
Status Codes, Error Codes and Error Messages
| Status Code | Error Code | Error Message |
|---|---|---|
| 400 | Request.BadRequest | Bad request. |
| 400 | InvalidCustomer.IdEmpty | Customer ID cannot be empty or invalid. |
| 400 | InvalidService.IdIncorrect | Service ID is empty or invalid. |
| 400 | InvalidService.IdPermission | Service ID cannot be found or is unknown. |
| 400 | Invalid.PolicyName | Policy name is required. |
| 400 | InvalidPriority.Unique | Priority value must be unique. |
| 400 | InvalidPolicy.TypeEmpty | Policy type cannot be empty. |
| 400 | InvalidPolicy.AccessType | Policy access type must be one of the following values: allow, deny, or token. |
| 400 | InvalidPolicy.MatchURLIncorrect | The matchUrlPath cannot be empty. |
| 400 | InvalidPolicy.Operator | Operator must be one of the following values: prefix, regex, equals or suffix. |
| 400 | InvalidPolicy.MatchUrlPathPatternsIncorrect | The MatchUrlPath patterns cannot be empty. |
| 400 | InvalidPolicy.Priority | Priority is required. |
| 400 | InvalidPolicy.IpRestriction | IP restriction format is incorrect, Supported formats: 172.31.31.0, 172.31.31.0/255.255.255.0, 172.31.32.0/24. |
| 400 | InvalidPolicy.GeoFormat | Geo restriction format is incorrect. |
Examples
Edit Access Control
Request
PUT /cdn/v1.0/services/74330/accessControl/261949 HTTP/1.1
{
"policyName":"access",
"matchUrlPath":{
"operator":"suffix",
"patterns":["/wp-content/web/"]
},
"matchQueryString":{
"operator":"prefix",
"patterns":["/"]
},
"type":"token",
"priority": 913,
"geoRestriction":"US,CN",
"ipRestriction":"172.16.12.1",
"anonymousIp":true,
"tokenSecret":"bdfy7r6jflo3iydy9zxigkl5m0hte6d423d45dfg6gavo07xvmtc4tzsdc9yxyjy",
"enabled":true
}
Successful Response Body
{
"policyId": 261949,
"policyName": "access",
"type": "token",
"matchUrlPath": {
"operator": "suffix",
"patterns": [
"/wp-content/web/"
]
},
"matchQueryString": {
"operator": "prefix",
"patterns": [
"/"
]
},
"priority": 913,
"ipRestriction": "172.16.12.1",
"geoRestriction": "CN,US",
"anonymousIp": true,
"tokenSecret": "bdfy7r6jflo3iydy9zxigkl5m0hte6d423d45dfg6gavo07xvmtc4tzsdc9yxyjy",
"enabled": true
}