{
  "summary": "LDAP joins external OIDC as a full login backend: the Auth tab can now point admin/approver login, step-up SSO/JIT, device-identity binding, and the allodctl CLI at a directory bind instead of an external IdP, with a Test Login button that verifies real credentials and group authorization before you commit to it. Directory Sync auto-discovers LDAP base DNs and detects the schema flavor (posixAccount/AD/etc.) with a one-click Detect Schema button, fixing a group-membership foreign-key bug along the way, and the Pull-from-VRM settings action now carries LDAP connection fields and reports the peer's actual auth state honestly instead of guessing. Settings can now be shared end-to-end encrypted directly between SWG and VRM. Email authenticity scoring folds in typosquat-link detection and tunes down the HTML/plain-text mismatch weight so it needs corroboration, reducing false positives. The dashboard merges JA4/JA3 into a single Fingerprints card and folds IDS/IPS into Threat Intel. New: a device that fails identity verification now lands on a real sign-in page on its very next request instead of getting a silently dropped connection, and the Linux desktop notification for identity verification is finally clickable. The LDAP sign-in page itself has also been restyled to match the rest of the admin UI instead of a generic unstyled form. Also hardens the Linux identity-verification notification against argument injection via a crafted filename or email subject in its title/body."
}
