Blocked addresses
Addresses refused on every server - by the network firewall for direct visitors, by Traefik behind a trusted proxy - and those that never are.
Reading needs Read only and changes need Full, unless an endpoint says otherwise. How to read this page.
GET /api/security/blocks
Section titled “GET /api/security/blocks”Blocks in force, or the history, newest first.
- Level: Read only
- Input:
?state=active|history&q=&limit=100&offset=0 - Returns:
SecurityBlockListDto
POST /api/security/blocks
Section titled “POST /api/security/blocks”Block an address or a range on every server; refused, with the reason, for one that is never blocked.
- Level: Full
- Input:
{address, minutes?: number|null (null: until lifted), note?, siteSlug?} - Returns:
201 SecurityBlockDto
DELETE /api/security/blocks/:id
Section titled “DELETE /api/security/blocks/:id”Lift a block; it does not count as a repeat.
- Level: Full
- Notes: Destructive
- Returns:
SecurityBlockDto
GET /api/security/never-block
Section titled “GET /api/security/never-block”The never-block list, and the addresses admins used the panel from in the last 30 days.
- Level: Read only
- Returns:
{items: NeverBlockDto[], admins: AdminAddressDto[]}
POST /api/security/never-block
Section titled “POST /api/security/never-block”Never block an address or a range; blocks on it are lifted.
- Level: Full
- Notes: Destructive
- Input:
{address, note?} - Returns:
201 NeverBlockDto
DELETE /api/security/never-block/:id
Section titled “DELETE /api/security/never-block/:id”Take an address off the never-block list.
- Level: Full
- Notes: Destructive
GET /api/security/firewall
Section titled “GET /api/security/firewall”Where every server stands: network layer loaded, HTTP only, off, not installed.
- Level: Read only
- Returns:
FirewallOverviewDto
POST /api/security/firewall/sync
Section titled “POST /api/security/firewall/sync”Load the list on every server now.
- Level: Full
- Returns:
FirewallOverviewDto
GET /api/security/check
Section titled “GET /api/security/check”Could this address be blocked - and if not, why not; is it blocked, and by which block.
- Level: Read only
- Input:
?address= - Returns:
SecurityCheckDto
GET /api/security/detection
Section titled “GET /api/security/detection”The detector: its mode, the addresses it watches, and its recent decisions - including why it did not block.
- Level: Read only
- Returns:
SecurityDetectionDto