device/fido: blink all authenticators

Previously, for requests that required UV or resident keys,
authenticators that did not support those features did not blink. We
know from previous experience that this confuses users because then
there's no difference between a broken authenticator and an inapplicable
one.

This change causes such authenticators to blink, guarded by the
WebAuthenticatorPINSupport feature flag. If the user selects one then,
for MakeCredential, we show an error explaining what feature the
authenticator is missing, and for GetAssertion we show the missing
credentials error on the basis that UV would have to have been set at
creation time if it were the correct authenticator(*).

This change also tightens up the logic generally and adds tests for
every combination of PIN state and UV request.

(*) this is not strictly true in CTAP 2.0: it's possible to create a
credential without UV and then require UV at assertion time. But that
would be bizzare behaviour by a site and I'm choosing not to add more UI
states to specifically explain it here.

Change-Id: I813ec7a53dc14d509033e3be5b026405d0d95c5b
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/1534243
Reviewed-by: Avi Drissman <avi@chromium.org>
Reviewed-by: Martin Kreichgauer <martinkr@google.com>
Commit-Queue: Adam Langley <agl@chromium.org>
Cr-Commit-Position: refs/heads/master@{#644994}
22 files changed