It is certainly a benefit that the server only ever sees encrypted data. I have also worked on E2EE for multi-device shared spaces, and the trickiest bugs weren't in the encryption itself, but in edge cases related to key distribution. I have two questions regarding this:
1. When a new client joins but fails to retrieve the workspace key (due to temporary network issues or a 404 error from the server, for example), does it ever generate a new key locally? We encountered exactly this scenario: a device "helpfully" created its own key and encrypted data with it, rendering the message unreadable to other members (without any error notification). We ended up changing the server behavior so that instead of returning a "key missing" response, it signals that the key exists and the client should wait for it.
2. How do you handle key revocation? If you invite someone and later remove them, do you rotate (update) the workspace key and re-wrap it for the remaining members, or does the old key still allow access to past content?