Turns a SAML assertion's SessionNotOnOrAfter into the instant the session
here must end by, with the clock-skew allowance.
An instant already passed, or one that does not parse, is refused.
the assertion's contents
{ at, refused, why }, at in epoch milliseconds or 0 for none
Forwards to
FederationSp.sessionBoundOf().