authenticatorData, clientDataJSON and signature
(base64url), publicKeyJwk, expectedChallenge, expectedOrigin,
expectedRpId, and optionally requireUserVerification,
previousSignCount and allowInsecure (accept RS1)
ok, every check with its result, whether the signature is
valid, the signature counter, the flags, and the algorithm checked with
(coseAlg, algorithm)
Verifies an authentication assertion (WebAuthn section 7.2).
Checks the client data type, challenge and origin, the RP ID hash, user presence (and verification when required), that the signature counter advanced when a previous one is given, and the signature over the authenticator data and the client data hash.