Sync user groups via OpenID Connect
OpenID Connect groups should be usable for proper non-redundant permission management.
For that they:
- should be assignable from GUI and CLI (the latter would be sufficient in the beginning)
- need to be passed on via OpenID Connect with the respective claims/keys/mappings
- be supported by the upstream tools - I would be surprised if Nextcloud does not support it, but Zulip and Wekan need to be checked