Merge pull request #2727 from apache/jwt-kty-check

Only trust the servers declaration of JWT key type