2475335443
`save_env_value` / `remove_env_value` already write the right FILE (`get_env_path()` honors the profile-home override, so a routed turn lands in `profiles/<p>/.env`, not the root -- #77490's premise), but the in-process mirror went to `os.environ` unconditionally. Under a multiplexed gateway a `/pair` grant mirrored into `DISCORD_ALLOWED_USERS` from profile B therefore published B's allowlist into the SHARED process env, and B's own installed scope never saw the new value. Add `_publish_env_value`: when multiplex is active and a secret scope is installed, update the installed scope mapping (so same-turn scope reads see the grant) and leave `os.environ` untouched; every other caller keeps the legacy `os.environ` publish. Replace the stale TODO in gateway/pairing.py.