(*TheAuth).Doctor(ctx) inspects the live Config and storage and returns a Report:
a summary count per severity and a list of findings, most serious first. Findings
carry counts and setting names only, never secrets, tokens or user identifiers.
Checks that need an optional storage capability are skipped when it is missing.
Use it
GET /auth/admin/doctor (needs Config.APITokens) returns the report as JSON
to a caller holding the root ability, by session or bearer token. See
examples/doctor-admin for an admin page next to /healthz.
CLI, for CI:
--fail-on or a request failure, 2 usage.
Colors are off unless stdout is a TTY (also --no-color, NO_COLOR).
Optional storage capabilities: UserCountStorage, DoctorAdminLister,
DoctorSessionCounter, APITokenStorage, TOTPStorage.
Findings
<a id=“signup-open_no_allowlist”></a>
<a id=“bootstrap-gate_off_no_users”></a>
<a id=“network-trusted_proxies_empty”></a>
<a id=“cookie-insecure_http”></a>
<a id=“csrf-disabled”></a>
<a id=“throttle-disabled”></a>
<a id=“throttle-lax”></a>
<a id=“password-min_length_low”></a>
<a id=“password-no_breach_checker”></a>
<a id=“mfa-admin_without_totp”></a>
<a id=“mfa-none_enabled”></a>
<a id=“session-ttl_long”></a>
<a id=“session-no_idle_timeout”></a>
<a id=“token-no_expiry”></a>
<a id=“token-expiry_beyond_year”></a>
<a id=“token-root_ability”></a>
<a id=“token-agent_beyond_24h”></a>
<a id=“token-expired_unpruned”></a>
<a id=“session-expired_unpruned”></a>
<a id=“crypto-encryption_key_missing”></a>
<a id=“audit-no_sink”></a>
<a id=“webauthn-rpid_mismatch”></a>
<a id=“redirect-allowlist_empty”></a>