Lock to return app_metadata

In order to align more closely with the OIDC specs, the id_token now doesn’t contain any non-OIDC claims, e.g. app_metadata. You do have the option of explicitly setting custom claims in the id_token via a rule; this is outlined further in the following doc: