3654209b78
Browsers cannot send custom X-Session-Id header on WebSocket connections, so decode the token payload to extract session_id. Add WebAuthn success/failure recording to support rate limiter counter resets.