This page intentionally does not trigger the leak test itself — the
trigger must run from a different origin (see
leaktest.cgt.io) that sets
rpId=rp.leaktest.cgt.io. That cross-origin mismatch is what
forces WebKit/the OS credential service to fetch this origin's
/.well-known/webauthn to check whether
the calling origin is permitted to use this rpId.
Current well-known file: