The project's own bar is full coverage, and the new code had drifted from it — notably every error path, which is exactly where a browser is least likely to go on purpose and an attacker is most likely to. Two real bugs surfaced, both of the same shape: a cache failure escaping as a 500 on the login page. - `credentials->find()` was called outside the try block in `finishLogin()`, so a store failure threw instead of reporting a failed ceremony. - `credentials->save()` was likewise unguarded in `finishRegistration()`, and there the consequence was worse: reporting success for a credential that was never stored, so the user would believe their passkey was registered and discover otherwise only at the next login. Both now degrade to a failed ceremony, matching the rule the rest of the class follows: a failure the user cannot act on must never look like a server fault. Coverage is now at 98.7% of lines; the remainder is pre-existing defensive catches in AcceptListener/AllowListener plus a couple of unreachable guards.