mod_http_oauth2: Strip unknown client metadata
Per RFC 7591
> The authorization server MUST ignore any client metadata sent by the
> client that it does not understand (for instance, by silently removing
> unknown metadata from the client's registration record during
> processing).
This was previously done but unintentionally removed in 90449babaa48
2c07bcf56a36d6e74dc0f5422e89bd61f4d31239 0.8-diverge
1656d4fd71d07aa3a52da89d4daf7723a555e7dd last-google-code-commit