Endpoints covered by an active exception are left unticked. Checks each selected endpoint from this browser: reachability, status code, response time, HTTPS and CORS, plus config consistency.
The
token / auth check (build 6.6) calls each route with no credentials and with invalid ones (both must be refused), then with valid ones,
and scores it two ways:
Strict (the endpoint itself refuses calls without a token or login) and
Practical (Strict, or CORS restricted and
IP restricted, so the world can't reach it).
Credentials… sets the login per host (e.g. a WordPress username and application password); kept in memory only. Then save the run as one audit record in History.
Walk Swagger & audit host also imports the host's back-end interfaces from its SystemConsole; tie them to endpoints on the
Interfaces page.
Browsers only let a page read a response when the target API allows this page's origin (CORS). When it doesn't,
the audit can still tell whether the endpoint is up, but not its status code.