569b4242a3
#111809 accepted any *.nousresearch.com https host once the operator's Portal override pointed at a non-production Portal. That let a network-provenance value — the Portal's refresh response — pick any Nous-owned host as the bearer recipient, including hosts that are not inference gateways. Owning the DNS suffix is not the same as being an authorized recipient, and the validator's threat model (an injected refresh response) is exactly the case a suffix rule fails to bound. The recipient is now the operator's own NOUS_INFERENCE_BASE_URL: a non-production host returned by the Portal is accepted exactly when it equals that override's host, otherwise the strict production set stands. The Portal override grants nothing by itself. What the operator gains over plain use of the override is that the Portal's value is then persisted and used for the pricing scope and proxy instead of being healed to production, and the per-turn "refusing inference URL host" warning stops. No environment is named in code. Raised on #111809 review. Tests: recipient match accepted, unrelated Nous host refused, no override refused, Portal override alone grants nothing, the match follows the profile scope under multiplexing; the widening cases are red on main. Docs row for NOUS_INFERENCE_BASE_URL. Co-authored-by: Ben Barclay <ben@nousresearch.com>