db3dadb337
Closes all remaining security gaps from the RFC 9420 audit:
1. Update proposal signature verification (RFC 9420 Section 12.1.2):
- Verifies LeafNode signature in Update proposals via verifyLeafNodeSignature()
- Ensures sender can only update their own leaf with properly signed data
2. GroupContextExtensions validation (RFC 9420 Section 12.1.7):
- Validates extension types against KNOWN_EXTENSION_TYPES whitelist
- Supports ratchet_tree (0x0001), required_capabilities (0x0002),
external_pub (0x0003), external_senders (0x0004), Marmot (0xF2EE)
- Rejects unknown extension types
3. Parent hash validation (RFC 9420 Section 7.9.2):
- Full per-node ParentHashInput computation:
encryption_key || parent_hash || original_sibling_tree_hash
- Walks the entire direct path verifying hash chain
- Exposed treeHashNode as internal for sibling hash computation
- Returns false (rejects) on any chain break
4. Message replay detection (RFC 9420 Section 9.1):
- Added consumedGenerations tracker (Map<sender, Set<generation>>)
- applicationKeyNonceForGeneration rejects already-consumed generations
- Prevents replaying messages within the same epoch
5. Welcome ciphersuite verification (RFC 9420 Section 12.4.3.1):
- Verifies Welcome.cipherSuite matches KeyPackage.cipherSuite
- Rejects mismatched ciphersuites before attempting decryption
All 120 MLS tests pass (41 interop + 79 unit), 0 failures.
https://claude.ai/code/session_01NocQDWj2Y92FugjfgazzL3