4346721117
_is_callback_user_authorized resolved the gateway's auth chain through _message_handler.__self__. For a secondary multiplexed adapter the message handler is a per-profile closure with no __self__, so the introspection silently fell through to the env-only fallback -- which knows nothing about config allowlists or the pairing store, denying every button caller on that profile (fail-closed, but wrong). Prefer the auth callback GatewayRunner already injects at connection time via set_authorization_check (registered for primary and multiplexed adapters alike, delegating to the full _is_user_authorized chain), and keep the introspection plus env fallback for adapters wired without it. Same resolution pattern the admin-tier gate uses.