WHAT: regression test mounting the kanban plugin router exactly as
`_mount_plugin_api_routes` does (behind `_plugin_route_secret_scope`) and driving
Specify under `set_multiplex_active(True)` for launch profile A -> `?profile=workerb`
-> A, asserting the aux call's `get_secret` sees each profile's own key.
WHY: `_run_aux` / `_run_estimate` only pinned the board, never a profile scope, so the
aux client's provider-key read failed closed under multi-profile hosting. The scope is
now bound once at the plugin mount (previous commit) rather than per aux call inside the
plugin: one mechanism for every plugin router, and the `?profile=` request convention
works for the kanban routes too.
Fixes#123372
(cherry picked from commit 6f01ddc9e455b3eee7046d5b1ac969df3499cbeb)