Reads the new `policies.forteapps.io/auth-oidc-allowed-return-hosts` pod
annotation into the OIDC sidecar's AUTH_OIDC_ALLOWED_RETURN_HOSTS env var
(mirrors the existing cookie-domain wiring). Enables origin-preserving
post-login redirects so a login that round-trips through a shared apex
callback returns the user to the originating subdomain.
Absent annotation => empty => unchanged path-only redirect, so all other
apps injected by this policy are unaffected. Requires auth-sidecar >= v1.5.0
(Forte/auth-sidecar#24) and the matching forteapp chart annotation.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>