* dns_netcup: add support for the new netcup REST API
Domains managed by the new DNS backend can be handled through the new
REST API at api.netcup.com. The API is selected by the length of
NC_Apikey: new REST API keys are 64 characters long, legacy CCP API
keys are 50.
With a REST API key the domain is looked up via GET /v1/domain and the
challenge record is managed through the dedicated ACME challenge
endpoints. After adding a record, the script waits 20 seconds and then
polls until the record reports the deployed status.
Domains whose DNS cannot be managed via the REST API yet fall back to
the legacy CCP API when NC_Apikey_Legacy, NC_Apipw and NC_CID are
configured.
* dns_netcup: treat non-challenge records as a no-op on the REST API
The REST API can only manage _acme-challenge records, records with
other names cannot exist behind it. The DNS-API-Test adds and removes
a TXT record outside _acme-challenge and expects both calls to
succeed, so treat such records as a successful no-op with an info
message instead of failing.
* dns_netcup: address review feedback for the REST API support
- Only skip the synthetic DNS-API-Test record: real records without
the _acme-challenge prefix (e.g. a challenge alias in the "=" form)
now fail loudly, or use the legacy CCP API when legacy credentials
are configured. The zone walk starts at the full name for them, so
an apex alias is found.
- Blank _H2..._H5 for REST API calls and clear all header slots before
legacy CCP API calls so no auth headers leak between endpoints or
dns hooks.
- Stop walking the zone lookup when the API reports success:false and
surface the response instead of a misleading "no zone found".
- Split the response before extracting id/isDnsManaged so the egrep
and sed implementations of _egrep_o cannot pick different matches.
- Fall back to the legacy CCP API only on a literal isDnsManaged
false; error distinctly on an unparsable value.
- Poll the deploy status right away and sleep between retries instead
of an unconditional 20 second sleep.
- Use ${#NC_Apikey} for the key length and rename internal state to
_nc_apikey/_nc_endrest.
* dns_netcup: walk on when the REST API reports resourceDoesNotExist
Querying /domain?fqdn= for a name that is not a domain of the account
does not return an empty result: the API answers with success:false
and the error code resourceDoesNotExist. Treat exactly that as "not
found" during the zone walk and keep failing hard on everything else,
e.g. an invalid API key.
The zone lookup walked the challenge name from the right and ended up
asking netcup for the full "_acme-challenge.<domain>" as a zone name.
That can never be a zone, so netcup answered 4013 "Validation Error",
which replaced the real 5028 "The zone <domain> could not be found" as
the error shown to the user.
Stop one label short of the full name, and fail explicitly when no zone
matched, reporting the last API response plus what to check. Before, a
run where every candidate returned 5028 fell through to logout and
returned success.
Instead of using comments declare info in a special variable.
Then the variable can be used to print the DNS API provider usage.
The usage can be parsed on UI and show all needed inputs for options.
The info is stored in plain string that it's both human-readable and easy to parse:
dns_example_info='API name
An extended description.
Multiline.
Domains: list of alternative domains to find
Site: the dns provider website e.g. example.com
Docs: Link to ACME.sh wiki for the provider
Options:
VARIABLE1 Title for the option1.
VARIABLE2 Title for the option2. Default "default value".
VARIABLE3 Title for the option3. Description to show on UI. Optional.
Issues: Link to a support ticket on https://github.com/acmesh-official/acme.sh
Author: First Lastname <authoremail@example.com>, Another Author <https://github.com/example>;
'
Here:
VARIABLE1 will be required.
VARIABLE2 will be required too but will be populated with a "default value".
VARIABLE3 is optional and can be empty.
A DNS provider may have alternative options like CloudFlare may use API KEY or API Token.
You can use a second section OptionsAlt: section.
Some providers may have alternative names or domains e.g. Aliyun and AlibabaCloud.
Add them to Domains: section.
Signed-off-by: Sergey Ponomarev <stokito@gmail.com>
* Create LICENSE.md
* remove _hostingde_parse_no_strip_whitespace function as this breaks API requests
* Fix sessionid parsing on BSD
* Make travis happy. (SC2020)
* fix for https://github.com/Neilpang/acme.sh/issues/2286
* Notify mail update (#2293)
* feat: disable e-mail validation if MAIL_NOVALIDATE is set
* fix: expose _MAIL_BIN variable
* fix: call _mail_body and _mail_cmnd directly to make sure that all used variables are exposed
* fix: update notify/mail.sh
Co-Authored-By: Matej Mihevc <zuexo@users.noreply.github.com>
* fix: remove useless echo, quote eval