Should KEYCLOAK_APPLICATION or KEYCLOAK_IDENTITY_REQUESTER be visible at all externally
(both in REST endpoints and admin console)?
I was thinking that these roles should be removed from the list of roles returned, and if
anyone tries to delete a role starting with "KEYCLOAK_" a not found should be
returned.