- app_super_admin is a new cross-app LDAP group (also recognized by
sso-manager-node and jump-host): added to conf.auth.adminGroups so
members are always global admins here, same as the existing anti-lockout
adminUsers/adminGroups mechanism.
- Users and Permissions pages: the always-visible sidebar "Add" forms are
now an "Add User"/"Add Permission" button in the list header that opens
an app.modal dialog, matching the hosts.ejs convention.
- The Let's Encrypt ACME account key now defaults to the already-persisted
/data volume (models/host.js) instead of a CWD-relative path
(./le_key.cert -> /app/le_key.cert in the container), which was lost on
every image rebuild. Falls back to the old relative path when /data isn't
present (e.g. local dev outside docker).