fixes from release/20 (#15982)
* Avoid path traversal vis double-url encoding of redirect URI (#8)
(cherry picked from commit a2128fb9e940d96c2f9a64edcd4fbcc768eedb4f)
* Do not resolve user session if corresponding auth session does not exist (#7)
* Stabilizing the ConcurrentLoginTest when running with JPA map storage by locking user sessions (#9)
Co-authored-by: Marek Posolda <mposolda@gmail.com>
Co-authored-by: Pedro Igor <pigor.craveiro@gmail.com>
Co-authored-by: Alexander Schwartz <alexander.schwartz@gmx.net>