Ported from validate_standalone_proposal_account_identity_proof (Add
branch; D-08/D-09): validates the 0x8009 proof of every Add proposal's
KeyPackage against ciphersuite, pure and non-throwing. Used pre-apply by
the standalone-proposal admission seams (src/engine/admin-policy.ts
inbound, src/engine/group-engine.ts local propose path) so a bad Add
never reaches the queued-proposal state in the first place — the commit-time
tree diff in validateCommitAccountIdentityProofs still catches it
after apply if either admission gate is bypassed, since both call the same
underlying validateKeyPackageAccountIdentityProof.
Accepts both bare Proposal and ProposalWithSender items (normalizes
each first) and ignores every non-Add proposal kind. Returns on the first
failing Add; leafIndex is always omitted (the KeyPackage has no tree
position yet, pre-apply).
Ported from
validate_standalone_proposal_account_identity_proof(Add branch; D-08/D-09): validates the0x8009proof of every Add proposal'sKeyPackageagainstciphersuite, pure and non-throwing. Used pre-apply by the standalone-proposal admission seams (src/engine/admin-policy.tsinbound,src/engine/group-engine.tslocal propose path) so a bad Add never reaches the queued-proposal state in the first place — the commit-time tree diff in validateCommitAccountIdentityProofs still catches it after apply if either admission gate is bypassed, since both call the same underlying validateKeyPackageAccountIdentityProof.Accepts both bare
ProposalandProposalWithSenderitems (normalizes each first) and ignores every non-Add proposal kind. Returns on the first failing Add;leafIndexis always omitted (the KeyPackage has no tree position yet, pre-apply).