the user member of the grant request
Optionalctx: any
the grant's context: { issuer, oauthIssuer, client }, the
client being the instance presenting it — a user reference resolves
only for the client it was issued to
{ ok: true, username, verified } (username null when nothing
resolved), or a refusal
Resolves an inbound
user(section 2.4) to a username.verifiedis true only when an assertion this realm signed named the person; an unresolvable sub_id is a hint that did not help, and an unknown reference isunknown_user.