A recipient opens the envelope with their X25519 private key. The server cannot run this — it
has no private key. Mirrors open_field in sealed_field.rs, including its two integrity gates:
the AAD is RE-DERIVED from the struct fields and must equal the stored one (anti-frankenstein:
swapping dfid/event/field/content_type/alg/schema makes the open fail);
the plaintext must match the hiding commitment recomputed with the DK.
A recipient opens the envelope with their X25519 private key. The server cannot run this — it has no private key. Mirrors
open_fieldin sealed_field.rs, including its two integrity gates: