Without this field, U2F just isn't working and the accounts with U2F set up are shown an OTP prompt.
There seems to be no good reason to change group membership when exchanging tokens, let's try just passing the old one over.
Allow loading remote images.
Simplifies the device manager code as we don't have to duplicate the IP/network matching logic there.
Should make the subdivision between apps (idp, sso) more obvious.
Uses the clientutil.Backend abstraction for the keystore client API.