* dns_netcup: add support for the new netcup REST API
Domains managed by the new DNS backend can be handled through the new
REST API at api.netcup.com. The API is selected by the length of
NC_Apikey: new REST API keys are 64 characters long, legacy CCP API
keys are 50.
With a REST API key the domain is looked up via GET /v1/domain and the
challenge record is managed through the dedicated ACME challenge
endpoints. After adding a record, the script waits 20 seconds and then
polls until the record reports the deployed status.
Domains whose DNS cannot be managed via the REST API yet fall back to
the legacy CCP API when NC_Apikey_Legacy, NC_Apipw and NC_CID are
configured.
* dns_netcup: treat non-challenge records as a no-op on the REST API
The REST API can only manage _acme-challenge records, records with
other names cannot exist behind it. The DNS-API-Test adds and removes
a TXT record outside _acme-challenge and expects both calls to
succeed, so treat such records as a successful no-op with an info
message instead of failing.
* dns_netcup: address review feedback for the REST API support
- Only skip the synthetic DNS-API-Test record: real records without
the _acme-challenge prefix (e.g. a challenge alias in the "=" form)
now fail loudly, or use the legacy CCP API when legacy credentials
are configured. The zone walk starts at the full name for them, so
an apex alias is found.
- Blank _H2..._H5 for REST API calls and clear all header slots before
legacy CCP API calls so no auth headers leak between endpoints or
dns hooks.
- Stop walking the zone lookup when the API reports success:false and
surface the response instead of a misleading "no zone found".
- Split the response before extracting id/isDnsManaged so the egrep
and sed implementations of _egrep_o cannot pick different matches.
- Fall back to the legacy CCP API only on a literal isDnsManaged
false; error distinctly on an unparsable value.
- Poll the deploy status right away and sleep between retries instead
of an unconditional 20 second sleep.
- Use ${#NC_Apikey} for the key length and rename internal state to
_nc_apikey/_nc_endrest.
* dns_netcup: walk on when the REST API reports resourceDoesNotExist
Querying /domain?fqdn= for a name that is not a domain of the account
does not return an empty result: the API answers with success:false
and the error code resourceDoesNotExist. Treat exactly that as "not
found" during the zone walk and keep failing hard on everything else,
e.g. an invalid API key.