Encrypt the file once; distribute the file key inside the MLS-encrypted group message. All members derive the same key from group state. Reuses the file subsystem with single-ciphertext group delivery.
Acceptance criteria:
- One file key shared via MLS to the whole group
- Members decrypt with the shared key
- Removed members lose access going forward (post-rekey)
Encrypt the file once; distribute the file key inside the MLS-encrypted group message. All members derive the same key from group state. Reuses the file subsystem with single-ciphertext group delivery.
Acceptance criteria: