Improvement according to Alex suggestions
- use and validate proxy prefix everywhere
- give preference to user annotations
- fix groups-claim
- remove custom return uri
- hardcode email domain
- remove upstream.service.path field
- document steps for manual integration tests
see !6 (closed)