Seal one field for N recipients. Pure crypto — no network, no storage. Mirrors seal_field
in sealed_field.rs step by step:
1 random DK → hiding commitment → canonical AAD → ciphertext = nonce || AEAD(DK, value)
→ one HPKE wrap of the SAME DK per recipient (1 vault, N padlocks — not N vaults).
The result carries an EMPTY sealer block: authorship is a separate step (signSealedField),
because the signing key (Ed25519) is distinct from the encryption keys and may be custodied.
eventId here is the CLIENT event id (a nonce you pick, e.g. a UUID) — the server assigns the
real event id after the POST and links it.
Seal one field for N recipients. Pure crypto — no network, no storage. Mirrors
seal_fieldin sealed_field.rs step by step:1 random DK → hiding commitment → canonical AAD → ciphertext = nonce || AEAD(DK, value) → one HPKE wrap of the SAME DK per recipient (1 vault, N padlocks — not N vaults).
The result carries an EMPTY sealer block: authorship is a separate step (
signSealedField), because the signing key (Ed25519) is distinct from the encryption keys and may be custodied.eventIdhere is the CLIENT event id (a nonce you pick, e.g. a UUID) — the server assigns the real event id after the POST and links it.