modeled like our other section config api calls two drawbacks of doing it this way: * we have to copy some api properties again for the update call, since not all of them are updateable (username-claim) * we only handle openid for now, which we would have to change when we add ldap/ad Signed-off-by: Dominik Csapak <d.csapak@proxmox.com>