_sync_ldap_user used to replace user.groups entirely on every login,
wiping manual admin assignments to groups outside the LDAP mapping.
Now partitions on LDAP-managed group names (mapping values + default
group) and only rebuilds that slice from LDAP truth. Manual assignments
to non-managed groups are preserved; revocation in LDAP still
propagates for managed groups.