- Added monitoring endpoints (including /subsz) with configurable HTTP base path and support for TLS domainComponent matching
- Introduced no‑auth user reference, close reason in connection close statements, and validation of configuration reload options
- Fixed leafnode loop detection, service interest propagation, remote gateway URL updates, and default permissions for NKey users