A full replacement, never a partial merge: every rule is re-applied to the whole
submitted descriptor, so a field left out reverts to its default rather than
keeping a value nothing re-checked.
š“ The issuer URL may not change. Everything else on a
declaration is a rule ABOUT one issuer and is editable in place; the URL is the
issuer's identity. Every actor binding resolves on the pair
(issuer, subject), so rewriting it here would stop every one of those
bindings matching ā and it would do so silently, because nothing fails: the row
updates cleanly, the console shows green, and the next token is refused with the
same undiagnosable 401 as a bad signature. Declare the new issuer, move the
bindings, then withdraw this one.
This changes a live authentication rule. Narrowing
permittedAlgorithms takes effect on the very next request, and
in-flight workloads whose tokens are signed with a removed algorithm begin being
refused immediately. The pre-change values are recorded in the audit trail, so an
incident can be answered with what the rules WERE.
The derivedAudience does not change: it follows the declaration's
scope, not its URL.
Entitlement-gated.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests⦠| |||