9be7cfd27a
Addresses critical security gaps identified in the RFC 9420 audit: 1. Epoch and group ID verification in decrypt (RFC 9420 Section 6.1): - PrivateMessage.epoch must match current group epoch - PrivateMessage.groupId must match current group ID - Rejects messages from wrong epoch/group immediately 2. Remove proposal sender authorization (RFC 9420 Section 12.1.2): - Cannot remove yourself via Remove (use SelfRemove) - Target leaf index must be in range and non-blank - Committer is implicitly authorized for inline proposals 3. KeyPackage lifetime validation (RFC 9420 Section 10.1): - Checks notBefore/notAfter against current time on Add proposals - Rejects expired or not-yet-valid KeyPackages 4. Unified proposal application in commit(): - commit() now uses applyProposal() for all validation - Same authorization checks apply to both commit() and processCommit() - addedMembers tracked before apply for Welcome generation All 120 MLS tests pass (41 interop + 79 unit), 0 failures. https://claude.ai/code/session_01NocQDWj2Y92FugjfgazzL3