FIDOv2 at al
- Add cache control for static files.
- Add global rate limit for password attempts.
- Use Origin header in preference to Referer.
- Add FIDOv2 protocol support for token registration and web authentication.
- Refactor AWS role certificate support into a package.
- Small documentation improvements.
- Other bugfixes.