Files
48966ba481 Add DNSMint DNS API (#7238)
* Add DNSMint DNS API

DNSMint mints hostnames on domains it operates and serves from its own
authoritative nameservers, so a customer has no zone of their own and the
challenge is published through its API.

The hostname is derived server-side from the challenge name, so there is
no root zone to detect and no record id to track: the value published is
the value removed. Wildcards work because the API keeps the two newest
values for a name, which is what the apex and wildcard pair needs.

Tested against Let's Encrypt staging for a wildcard plus its apex.

* Add DNSMint DNS API

DNSMint mints hostnames on domains it operates and serves from its own
authoritative nameservers, so records are published through its API
rather than a zone you run.

An ACME challenge goes to the DNS-01 endpoint, which derives the hostname
from the challenge name: no root zone to detect, no record id to track,
and the value published is the value removed. Wildcards work because the
API keeps the two newest values for a name.

Any other TXT name is an ordinary record under a hostname and goes to the
records endpoint instead, which is why the add and rm functions branch on
the _acme-challenge label. Issuing certificates needs only the dns01:write
scope; the record endpoint needs hostnames:read and hostnames:write.

Tested against Let's Encrypt staging for a wildcard plus its apex, and
the non-challenge TXT path against the live API.

* dnsmint: honour DNSMint_Api instead of overwriting it

The assignment was unconditional, so exporting DNSMint_Api did nothing - the
plugin reset it to the default every time it was sourced. Every neighbouring
plugin with an _Api variable treats it as an override; this one only looked
like it did.

Found while writing the dnsapi2 entry: the sentence documenting the override
would have been false.

* dnsmint: format case blocks with shfmt -i 2

* dnsmint: portable record lookup on removal

grep -F is not on Solaris /usr/bin/grep, and "\n" in a sed replacement is a
GNU extension that BSD sed writes as a literal n. The second is the one that
loses data: without the split the whole reply stays on one line, so the match
succeeds whatever the value is and the id taken is the first record under the
hostname rather than the one holding the challenge. Removal then deletes
somebody else's TXT record.

Literal newline in the replacement, as dns_glesys.sh does it, and a case
pattern per line with the case outside a command substitution.

Docs and Issues now point at dnsapi2 and at the tracking issue upstream.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* dnsmint: echo into sed, and keep _head_n 1 on the id

Both from review on #7238.

The reply arrives with no trailing newline, so printf "%s" hands sed an
incomplete final line. Solaris /usr/bin/sed discards one, and here that line
is the whole reply: the loop then sees nothing and every removal reports the
record already gone, leaving the challenge TXT behind. echo, as lines 154 and
172 of this file already do.

_head_n 1 was dropped in 61ef816c. A record object carrying a nested id under
"data" makes _rid two lines and the DELETE URL is then malformed.

---------

Co-authored-by: kxbnb <hello@dnsmint.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
48966ba481 · 2026-09-19 15:45:02 +02:00
History
..
2024-10-13 17:41:22 +02:00
2024-11-09 18:22:01 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2026-03-22 11:36:29 +08:00
2026-07-17 12:38:14 +08:00
2024-10-13 17:55:22 +02:00
2026-07-04 16:54:05 +08:00
2026-06-05 22:02:14 +02:00
2025-11-20 00:29:44 +08:00
2026-07-12 16:13:42 +08:00
2024-10-13 17:41:22 +02:00
2026-07-17 12:38:14 +08:00
2025-11-03 18:14:27 +01:00
2026-07-17 12:38:14 +08:00
2024-10-13 17:49:29 +02:00
2026-09-19 15:45:02 +02:00
2024-05-27 12:45:01 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2026-09-04 14:51:30 +08:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:49:29 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:49:29 +02:00
2024-10-13 17:41:22 +02:00
2026-07-17 12:38:14 +08:00
2026-07-17 12:38:14 +08:00
2024-10-13 17:49:29 +02:00
2024-10-13 17:41:22 +02:00
2025-07-02 21:15:46 +08:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:49:29 +02:00
2024-10-16 11:49:29 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:58:19 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:58:19 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2026-09-11 11:49:47 +08:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2026-07-17 12:38:14 +08:00
2025-12-30 16:31:16 -05:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2026-07-17 12:38:14 +08:00
2024-10-13 17:49:29 +02:00
2024-10-13 17:58:19 +02:00
2026-07-17 12:38:14 +08:00
2026-07-17 12:38:14 +08:00
2024-10-13 17:59:25 +02:00
2026-05-24 22:20:40 +02:00
2026-03-03 05:31:51 -08:00
2026-07-17 12:38:14 +08:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2026-07-17 12:38:14 +08:00
2024-10-13 17:41:22 +02:00
2024-10-13 17:41:22 +02:00
2024-12-28 17:42:58 +02:00
2020-01-30 12:06:39 +08:00