* fix: propagate OIDC attributes to STS session token * refactor: apply PR suggestions for STS session claims