- Fix LDAP/MSAD account propagation and allow disabling LDAP‑backed users when importEnabled=false.
- Resolve NullPointerException in identity brokering, correct user ID changes when federationLink/LDAP ID is missing, and fix JavaScript adapter PKCE parameter handling.
- Fix missing configmap read permission for the Keycloak operator role and other minor bugs.