a89706e4cb
The synchronous card-action handlers and the update-prompt resolver authorized clicks with _allow_group_message(), which answers "may this sender chat in this group?" — with group_policy=open it returns True for everyone. The approval resolver already used the correct operator gate (_is_interactive_operator_authorized), so the three code paths disagreed: with an open group policy an out-of-allowlist click on an update-prompt card was fully executed, and approval clicks returned a resolved-looking card before being rejected asynchronously. Authorize all three paths with _is_interactive_operator_authorized(), which checks membership of admins ∪ allowed_group_users (wildcard and the empty pairing-mode allowlist keep their existing allow semantics, matching _admit's DM pairing default). A missing operator identity now fails closed on the update-prompt resolver instead of skipping the check. Fixes #96045