Files
hermes-agent/hermes_cli/web_routers
teknium1 5ca670b398 fix(dashboard): profile-routed routers run under the profile's secret scope; console send never writes the process env
_config_profile_scope bound only HERMES_HOME, so GET /api/config?profile=B
expanded B's `${VAR}` refs to the dashboard (DEFAULT) profile's plaintext
credentials, WS /api/console commands for B saw the default's keys wherever B
lacked one, and the audio speak-stream synthesis thread re-resolved the TTS key
unscoped. Console `send` for B went further: send_cmd._load_hermes_env copied
B's .env into the shared os.environ with override=True, so every later
default-profile read saw B's tokens.

- web_server_profiles._config_profile_scope binds home + hydrated secret scope
  for a named profile and flips the process to fail-closed multi-profile
  hosting (same activation as the tui_gateway); the dashboard's own profile then
  runs under its frozen-launch-env scope. A single-profile dashboard stays
  unscoped (systemd / op-run credential injection keeps working).
- GET /api/tools/toolsets computes the per-toolset "configured" flag inside
  the profile scope (it was read after the scope closed).
- web_routers/mcp._profile_secret_scope now just delegates (no second copy of
  the composition); audio `_produce` runs the whole synthesis body under the
  requesting profile's scope, not only the resolve step.
- send_cmd._load_hermes_env targets the installed secret scope when one is
  active (gateway.config._getenv reads the scope first), os.environ only for
  the standalone CLI.
2026-09-15 03:46:29 -07:00
..