* Tweak AWS OIDC instructions
* Only contents: read is necessary
* Remove :aud filter because it's set to "sts.amazonaws.com" when using aws-actions/configure-aws-credentials
* Update to be valid JSON, and actually remove :aud
Co-authored-by: hubwriter <hubwriter@github.com>