method, clientId, presentedSecret and clientSecret, the
assertion (assertion, assertionType, jwks, jwksUri,
assertionJwks, audiences, strictAudience, issuer), the SAML
certificates, the TLS facts (certificateThumbprint, subjectDn,
tlsSubjects, applicationIdentifier) and request
a promise of { ok: true, method, ... }, or { ok: false, errorCode, description }
Decides whether what a request presented proves the client, by the method its entry declares. Whether authentication is required is
oauth2_bcp.js's question, not this one.