2bade5daa7
`langfuse._secret` and `azure_identity_adapter._scoped_env` were changed to raise rather than fall back, because swallowing `UnscopedSecretError` hides the spawn-site bug the exception exists to surface. `_scoped_setting` looked like it contradicted that, so make the split explicit and pin it. Hindsight already follows the contract for everything that decides WHERE data goes: `mode`, `apiKey` and the `bankId` partition read through bare `get_secret`, so a scopeless multiplexed read raises. In `_load_config` that raise happens on `HINDSIGHT_MODE` before any shaping value is reached, so the swallow below cannot mask an isolation failure. Presentation shaping is deliberately not in that class. `MemoryManager._each_provider` logs an `initialize` failure at WARNING and drops the provider for the session, so raising there would cost the whole memory provider because a speaker prefix could not be resolved. It degrades to the provider's own default instead — never to `os.environ`, which under multiplex is the default profile's. The test names the offending key rather than asserting that something raised: routing `mode` through the shaping helper shifts the failure to `HINDSIGHT_API_KEY`, which a bare `pytest.raises` would still accept.