288fdc1a4c
A token minted by a non-production Portal is meant to be spent at that environment's own inference gateway, and the Portal's refresh response names that host. The allowlist applied to Portal-returned inference URLs was production-only, so the value was refused as "not in allowlist" and healed to the production host — a token the production Portal never issued, sent to the production gateway, which 401s it. Every hosted non-production instance hit this on every gateway turn once #108319 made the deploy-wide NOUS_INFERENCE_BASE_URL invisible inside a routed profile scope (by design, #65941). The widening is keyed on the operator's trusted HERMES_PORTAL_BASE_URL override, never on the stored portal_base_url: when that override names a Portal outside the production allowlist, any https host under the Nous domain is accepted; otherwise the strict production set stands. So a poisoned auth.json cannot widen the set, a production-Portal session that finds a foreign inference URL in its state is still refused and healed, and the bearer can only ever go to a Nous-owned host. No environment is named in code. Because the override is read through the profile scope (previous commit), each multiplexed profile decides for itself. Validation: 4 invariant tests (accepted only under a non-production override; look-alike domains, dotless suffix and http still refused; stored portal alone does not widen; the decision follows the profile scope under multiplex) — the new-behaviour ones red on the previous commit. Main's existing validation tests are unchanged and green. Live receipt for the symptom and the fixed chain on a hosted instance: #111589. Based on #102863 and its rebase onto the decomposed auth_nous.py in #111589, whose portal-keyed pairing this replaces with the same behaviour and no environment literals. Co-authored-by: Ben Barclay <ben@nousresearch.com>