Replaces the declaration in full. Not a partial merge: every admission rule is
re-applied to the whole submitted descriptor, so a replace cannot leave a field at
a value nothing checked.
š“ The issuer URL may not change. Everything else on a declaration is a
rule about one issuer and is editable in place; the URL is the
issuer's identity. Every actor binding, in every tenant, resolves on the pair
(issuer, subject), so rewriting it would stop all of them matching ā silently,
because nothing fails: the row updates cleanly, the console shows green, and the
next token is refused with the same undiagnosable 401 as a bad signature. Withdraw
and declare the new URL instead.
Narrowing permittedAlgorithms or lowering
maximumTokenLifetime takes effect on the very next request, for every
tenant at once. The pre-change rules are recorded in the audit trail, because an
entry naming only the new state cannot answer the question an incident asks.
Never entitlement-gated. No Edition widens or narrows this plane. These are
the deployment operator's own declarations rather than a tenant's, so there is no
Edition to consult (FR-181.16).
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests⦠| |||