When alpha config injects request/response headers from OIDC claims,
users must manually duplicate those claim names into each provider's
additionalClaims list or get empty values. This is error-prone and
undocumented.
collectHeaderClaimsIntoProviders scans InjectRequestHeaders and
InjectResponseHeaders for ClaimSource entries, skips built-in
session fields (email, groups, etc.), and appends the remainder
to every provider's AdditionalClaims list with deduplication.
Signed-off-by: June Kim <kimjune01@gmail.com>