bebf229826
1. KeyPackage signature verification (RFC 9420 Section 10.1):
- Added MlsKeyPackage.verifySignature() using SignWithLabel("KeyPackageTBS")
- proposeAdd() now requires valid KeyPackage signature
- Fixed createKeyPackage to sign correct KeyPackageTBS (full TBS struct,
not just LeafNode bytes)
2. GroupInfo signature verification (RFC 9420 Section 12.4.3.1):
- Added GroupInfo.encodeTbs() and verifySignature(signerKey)
- processWelcome() verifies GroupInfo signature using signer's
leaf node from the reconstructed tree
3. Parent hash validation infrastructure (RFC 9420 Section 7.9.2):
- Added verifyParentHash() with simplified validation for leaf's
parent_hash field against the first direct path node
4. Graceful decrypt error recovery:
- Added decryptOrNull() that returns null instead of throwing on
corrupted messages, wrong epoch, or AEAD failures
All 120 MLS tests pass (41 interop + 79 unit), 0 failures.
https://claude.ai/code/session_01NocQDWj2Y92FugjfgazzL3