Enable OIDC and RS256 JWT signing from django-oauth-toolkit with a
single RSA key. Key rotation is not yet enabled and will be introduced
on the first rotation.
The JWT signed token contains the previous claims exposed in profile/v1
endpoint but compatible with the OIDC standard claims.
https://openid.net/specs/openid-connect-core-1_0.html#StandardClaims
* stub in poetry for pipenv
* re-add tester image
* add pre-commit / formatting
* fix ghactions
* revert test data whitespace, exclude tests/data
* revert ws
* decruft, rm tox/pipenv
* install dev packages for base image
* add lgtm config to force to py3