Cannot save attributes for LDAP user

Hi all,

I have a LDAP user federation, with edit mode set to READONLY, since I don´t want to write changes on username, email, first name, last name, and other mapped attributes back to the LDAP.

Now when I try to add a new attribute to a user of that user federation, I get a “Error updating group User is read only!”.

I´m a bit confused , since the documentation states for edit mode READONLY:

You cannot change the username, email, first name, last name, and other mapped attributes. Keycloak shows an error anytime a user attempts to update these fields.

But the attribute I tried to add is definitely not a mapped attribute.

Is this a bug?

Regards
Lars