The bridge wrote GATEWAY_ALLOW_ALL_USERS into os.environ only when unset and never cleared it. In-process restart paths (gateway restart watcher, dashboard profile actions) copy os.environ into the child, so a config.yaml grant became a sticky env var: flipping allow_all_users to false and restarting left the gateway OPEN. The bridge now tracks its own write (module flag), overwrites or clears it on reload, exports only a truthy grant (presence-based readers such as the Telegram intake prefilter treated "false" as configured auth), and the two restart env builders drop the bridge-owned value so the child re-derives the posture from its own config.yaml. Under multiplex_profiles the DEFAULT profile's events are authorized inside its secret scope, where gate readers never fall to os.environ; the bridged grant is now seeded into that profile's scope mapping only (secondaries never inherit it). Review finding: bridged GATEWAY_ALLOW_ALL_USERS survives restart and overrides a flipped config.yaml; inert for the default profile under multiplex; "false" exported as configured auth.
Website
This website is built using Docusaurus, a modern static website generator.
Installation
yarn
Local Development
yarn start
This command starts a local development server and opens up a browser window. Most changes are reflected live without having to restart the server.
Build
yarn build
This command generates static content into the build directory and can be served using any static contents hosting service.
Deployment
Using SSH:
USE_SSH=true yarn deploy
Not using SSH:
GIT_USER=<Your GitHub username> yarn deploy
If you are using GitHub pages for hosting, this command is a convenient way to build the website and push to the gh-pages branch.
Diagram Linting
CI runs ascii-guard to lint docs for ASCII box diagrams. Use Mermaid (````mermaid`) or plain lists/tables instead of ASCII boxes to avoid CI failures.