- Added new kube exec proxy mode for tsh, automatic role access requests, and Machine ID workload identity support for legacy systems.
- Updated UI behavior: cluster selector now appears only when multiple clusters exist, hide single-cluster name in Connect, redesign login UI, and made S3 fields optional in AWS OIDC integration; also fixed Windows desktop login display bugs.
- Fixed several bugs including accidental passkey downgrade to MFA, invalid session TTL errors, and other regressions related to access request creation and login handling.