Files
hermes-agent/gateway
liuhao1024 b483f0f65b fix(gateway): authorize a secondary bot's callbacks under its own profile scope
Under multiplex_profiles, a secondary profile that owns its own Telegram bot
gets its auth callback from _make_adapter_auth_check(profile_name=...), but
that branch ran _is_user_authorized with NO profile scope installed: the
callback is built at configure time and invoked from the adapter's event
loop, outside _profile_runtime_scope. The gate's scoped env read therefore
fell back to os.environ — the default profile's env — so an allowlisted
caller tapping an inline button (exec approval ea:) was refused with the
'bot is private' toast, while plain text messages from the same user in the
same DM were authorized (their handler runs inside the scope). This is the
per-credential secondary-bot row of the transport matrix; the shared
primary row was fixed in 74775df53f (#86296).

The secondary branch now re-enters the owning profile's runtime scope per
call, mirroring _make_profile_message_handler. The secret scope is prebuilt
at configure time so entering it in the callback never does file IO on the
event loop; an unresolvable profile home keeps the fail-closed behavior of
every other secondary handler. (#120639)
2026-09-26 06:41:34 +05:30
..