Atomic, authority-scoped seven-day revocation hold. Durable implementations
must key by authority and publisher_domain, preserving first observation
across changed publisher timestamps, and reject on storage failure instead of returning an empty set.
Capture tenant identity from trusted application context in the store instance;
include that tenant in every key and transaction. Publisher evidence must never select a tenant.
Persist revoked_at as publisher metadata that may be the unspecified sentinel;
maintain the seven-day first-observation expiry in a separate timestamp column.
Atomic, authority-scoped seven-day revocation hold. Durable implementations must key by authority and publisher_domain, preserving first observation across changed publisher timestamps, and reject on storage failure instead of returning an empty set. Capture tenant identity from trusted application context in the store instance; include that tenant in every key and transaction. Publisher evidence must never select a tenant. Persist
revoked_atas publisher metadata that may be theunspecifiedsentinel; maintain the seven-day first-observation expiry in a separate timestamp column.