Store the avatar URL advertised by the provider and let each user's browser fetch the image directly from the provider. The provider must therefore be reachable from the browser, and the provider's domain is added to the img-src Content Security Policy directive. This is the default, and matches the behaviour of earlier releases of this plugin.