- OidcUserInfo now includes allClaims map from id_token + access_token - OidcAuthController.callback() calls applyClaimMappings instead of syncOidcRoles - applyClaimMappings evaluates rules, clears managed assignments, applies new ones - Supports both assignRole and addToGroup actions Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>