AD FS userinfo returns only sub; profile attributes live in the ID
token as upn/unique_name/given_name/family_name. Extract those claims
alongside the standard set on both token and userinfo payloads, and
resolve email across email/upn/unique_name candidates — accepting
upn/unique_name only when email-shaped since DOMAIN\user forms cannot
serve as addresses. Display name falls back to given_name+family_name,
nick to preferred_username/unique_name before the email local part.
Generated with [Devin](https://devin.ai)
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>