feat(release): check the oauth client metadata against every shipped id master
The extension bundles oauth/client-metadata.json and validates its own runtime redirect URI against it, so metadata that does not cover the id an install runs under throws "Invalid redirect_uri" before the authorization request is pushed. That is invisible to every server-side check: the hosted metadata and the OAuth server are both fine. Declare the ids the extension ships under in oauth/extension-ids.json and check them three ways: the unpacked id is derived from the manifest key rather than trusted, every declared id has a redirect URI (and every redirect URI a declared id), and the built JS carries both. The bundle check is the only one that inspects the artifact being uploaded rather than the sources it should have come from.