Typically, LDAP servers ignore spaces in usernames, and thus, attempting to bind with username "jstubbs" or username "jstubbs " and the correct password will succeed. However, this results in Tapis JWTs with different usernames, and thus, different subjects, causing many problems. We should update authenticator to reject usernames that contain spaces in the same way that we reject mixed-case usernames for a similar reason.