9ca11399c0
With gateway.multiplex_profiles enabled, the primary Telegram message handler is the closure returned by _make_default_profile_message_handler(), so its __self__ is absent. The early intake filter (_is_user_authorized_from_message) recovered the GatewayRunner via self._message_handler.__self__ and, finding none, fell back to env-only authorization — never evaluating the configured chat allowlist through GatewayRunner._is_user_authorized(). Every non-global sender was then default-denied in an explicitly allowlisted group. Prefer the platform-bound authorization callback registered via set_authorization_check(): it routes through the runner's full auth chain (platform + group allowlists, pairing store, allow-all) and survives the closure wrapping, whereas the bound-handler lookup does not. The bound handler remains the fallback for setups without a registered callback, and the pairing-passthrough guard for unknown DMs is preserved. Fixes #87132