This patch will allow the web api to (optionally) fall back from HTTPS
to HTTP under very particular circumstances:
1. The appropriate `insecure` flag was set, and
2. The target host is the loopback
If both conditions are met, this patch will allow the WebAPI client to
fall back to plain HTTP when attempting to login to the auth server.
- Implemented `DeleteMFADeviceSynce`, which takes in a token
that allows users to delete devices during the recovery process
- Refactored `GetMFADevices` to take in recovery token
- Pulled out deleting MFA device (from stream version) into helper func to be re-used
- Added delete MFA web handler
The purpose of this commit was to remove the lib/client dependency of
lib/web.
lib/client must be dependency-free in order to be reusable.
Next step: make the web UI use the same client code as the CLI. This
will remove a ton of duplicate code making Teleport audit surface area
much smaller.