ReadonlymediaDecrypts a fetched blob for a parsed attachment, verifying its ciphertext
and plaintext hashes, and caches the plaintext keyed by ciphertextSha256.
The media file key is bound to the message's source-epoch media exporter
secret, which is not carried in the imeta tag. This derives one candidate
key per still-retained epoch (current epoch first) and lets the AEAD tag
select the right one, so media sent before the local tip advanced still
decrypts. Media from an epoch already pruned past the rollback horizon
cannot be decrypted.
Encrypts a blob for sharing in a group message. The returned attachment has
its hashes, nonce, media type, and filename set but no locators — the
caller uploads encrypted to a blob store, adds a MediaAttachment
locator, then serializes it with encodeMediaImetaTag.
Optional group-scoped encrypted-media helper and plaintext cache adapter.
On send, the media file key is derived from the group's CURRENT
ClientState— the source epoch is the current epoch. On receive, the source epoch is the MLS epoch of the message that carried the attachment, which is not encoded in theimetatag (features/encrypted-media.md— Key Derivation). Rather than thread that epoch through every caller, decryptMedia derives one candidate key per still-retained epoch and lets the AEAD tag pick the right one, so media sent before the local tip advanced still decrypts. Media from an epoch already pruned past the rollback horizon cannot be decrypted.