Checks an assertion's audience restrictions: every restriction must name
this service (ourEntityId() or fedClientId), in every mode.
the assertion element
the service's base URL
the federation relationship
whether an assertion with no audience restriction is refused (SAML 2.0) rather than accepted with a warning
{ ok, why }, with errorCode on a refusal
Forwards to
FederationSp.audienceCheck().