currently the strategy reissues coa capability on `_getCOACapability` consider using user's coa to shift trust boundary