Reconstruct the trusted-verifier set instead of trusting every issuer master
The earlier verification pass counted any issuer, which would show false badges (e.g. bsky.app had 54 raw verification records, 53 from untrusted accounts). Trust is actually expressed on-network: Bluesky's root DID issues a verification record to each trusted verifier, who can then verify regular users. So a verification of X by issuer I counts only if the root DID verified I. This is a two-hop backlink lookup, fully reconstructable from Constellation with no private allowlist - the only constant is the root DID itself. hydrateVerificationState now filters verifications to trusted issuers and sets the subject's trustedVerifierStatus from whether the root verified it directly. Verified: bsky.app/nytimes/wired each collapse from raw records to exactly 1 trusted verification, all trustedVerifierStatus=valid.