Type Alias AccountIdentityProofRejectReason
AccountIdentityProofRejectReason:
| "invalid-credential"
| "legacy-extension-present"
| "invalid-dictionary"
| "duplicate-data"
| "missing-support"
| "missing-data"
| "invalid-location"
| "ciphersuite-mismatch"
| "signature-key-mismatch"
| "identity-mismatch"
| "invalid-proof"
| "legacy-group"
| "mixed-profile"
| "missing-requirement"
| "member-identity-changed"
| "unattributable-leaf"
The reason a
0x8009account identity proof (or a GroupContext/KeyPackage location check) was rejected. One literal per spec validation step — never a coarse bucket. The nine D-13 minimum reasons (invalid-location,missing-support,missing-data,duplicate-data,ciphersuite-mismatch,signature-key-mismatch,identity-mismatch,invalid-proof,legacy-extension-present) are all present;invalid-credential,invalid-dictionary,legacy-group,mixed-profile, andmissing-requirementare the additions D-13 allows.Phase 9 (UPD-01) adds two more, both emitted by the commit-legality bucket classifier in
./integrity.js, not by any validator in this module:member-identity-changed(D-05): the replacement leaf at an existing member's index carries a different account identity than the leaf it replaced. Deliberately NOTidentity-mismatch— that literal means the proof's signer does not match this leaf's own credential identity (a single-leaf check). Conflating the two would collapse a membership-model violation into a proof-binding error.unattributable-leaf(D-02): a changed leaf that, with the commit's full proposal list and committer index available, matches no Add proposal, no Update proposal sender, and is not the committer's update-path leaf — fail closed.