Issues a challenge bound to the session and the person, replacing any earlier one this session holds for the same purpose.
purpose (key or webauthn), sessionId, username, and detail to carry along (a WebAuthn link's credential and target)
purpose
key
webauthn
sessionId
username
detail
{ ok, challenge, purpose, expiresAt, detail }, or a refusal { ok: false, status, error }
{ ok, challenge, purpose, expiresAt, detail }
{ ok: false, status, error }
Issues a challenge bound to the session and the person, replacing any earlier one this session holds for the same purpose.