b1bc9bb650
Route every GOOGLE_CHAT_* / GOOGLE_APPLICATION_CREDENTIALS read through a module-local `_get_scoped_secret` (scope-authoritative under multiplex, os.environ fallback only for the unscoped default-profile constructor, so startup/reconnect never hits UnscopedSecretError — #70652 class). Snapshot Pub/Sub callback knobs on the instance while the scope is still installed, and seed them into `extra` from `_env_enablement`. When a scoped profile has no service-account setting, do NOT fall through to google.auth.default(): ADC reads the process env directly and would authenticate the profile as another profile's SA. Fail closed with an explicit error (adapter and standalone send). Also resolve the bot-id cache path at call time via get_hermes_home() so profiles don't share one identity cache. Fixes #73439. Salvaged from #73445 (Jony) with the ADC guard from #57674 (Ray, first submitter). Co-authored-by: Ray <rayjun0412@gmail.com>