Variant of encrypt_blob_cipher that accepts an explicit outer wrapping
key. Used by key rotation, where the new user/org key is installed under a
Local slot id β key_identifier() would resolve to the original
User/Organization slot and wrap the cipher key under the old key.
Seals a constructed CipherBlobLatest under cipher_key, returning the
opaque string form. Shared by all CipherBlobLatest producers so they
donβt each re-implement the versioned-enum wrap + COSE seal + base64 chain.
Seals a CipherView into an opaque blob string under the given cipher_key slot.
The caller is responsible for loading the key slot before calling (e.g. via
CipherView::load_cipher_key_slot); this avoids allocating a duplicate slot.