Comment on While running passkey with native api, what type (or format) of origin information returned in ClientDataJSON? So, RP is not in charge of validating the origin with given RPID in case of the response is coming from the native application? Instead, the platform validates associated domain and calling application? Do I understand it correctly? Privacy & Security General Nov ’22