Chooses the username a federated person is filed under: from
fedUsernameSource or the subject, normalised through identityKeyOf(),
then prefixed by federation.usernamePrefix.
A urn:uuid: subject becomes sub-<uuid> rather than being resolved in
this realm's directory. A configured source the assertion did not carry
falls back to the subject, with a warning.
the federation relationship
the flattened incoming values
Optionalsubject: unknown
the subject the protocol carried
{ username, raw, from, prefixed }
Forwards to
FederationMap.usernameFor()on the installed instance.