- remove forced re-login after user group changes and group scope updates by refreshing live permissions in place
- fix scoped Docker and node permission handling across sidebar, routes, command palette, container detail tabs, and realtime updates
- harden backend permission checks to use effective scopes for certificate visibility and related restricted views