[webauthn] Clarify uses of ClientData

== Clarify uses of ClientData ==
As per https://w3c.github.io/webauthn/#sec-client-data,

"The client data represents the contextual bindings of both the 
Relying Party and the client platform."  This implies that 
authenticator contextual bindings are not included in the ClientData.
  Moreover, all dictionary entries listed in this section (challenge, 
rpId, etc.) do not represent values that are set by the authenticator.

Yet ihttps://w3c.github.io/webauthn/#sec-android-attestation-signature
 defines platform-specific extensions to ClientData that are 
authenticator specific, which implies a contextual binding of the 

My suggestion is to prohibit such platform-specific extensions to 

