detail is a diagnostic string naming component ids and counts only — never
raw pubkeys or other protocol-sensitive material (diagnostics-privacy rule,
see foundation/errors.md). The protocol-visible signal is reason.
proofReason and leafIndex are populated only for reason: "account-identity-proof" violations (D-06), by
validateCommitAccountIdentityProofs and
validateAddProposalAccountIdentityProofs. Both are pubkey-free:
proofReason is the caught AccountIdentityProofError.reason literal
and leafIndex is the failing leaf's true MLS tree leaf index (./tree-diff.jsdiffChangedLeaves's leafIndex — never the member-enumeration index
validateGroupMemberAccountIdentityProofs uses internally). leafIndex is
omitted for a profile-drift violation (no single leaf is at fault) and for a
pre-apply Add-proposal violation (the leaf has no tree position yet).
A typed, non-throwing violation returned by validateAppComponentIntegrity, validateAdminLeafCoupling, or validateCommitLegality.
detailis a diagnostic string naming component ids and counts only — never raw pubkeys or other protocol-sensitive material (diagnostics-privacy rule, see foundation/errors.md). The protocol-visible signal isreason.proofReasonandleafIndexare populated only forreason: "account-identity-proof"violations (D-06), by validateCommitAccountIdentityProofs and validateAddProposalAccountIdentityProofs. Both are pubkey-free:proofReasonis the caught AccountIdentityProofError.reason literal andleafIndexis the failing leaf's true MLS tree leaf index (./tree-diff.jsdiffChangedLeaves'sleafIndex— never the member-enumeration indexvalidateGroupMemberAccountIdentityProofsuses internally).leafIndexis omitted for a profile-drift violation (no single leaf is at fault) and for a pre-apply Add-proposal violation (the leaf has no tree position yet).