aaa5f27d0f
Under gateway.multiplex_profiles the default profile's YAML-to-env bridge writes BUZZ_* values into os.environ, and every Buzz read gave that env precedence over the secondary profile's PlatformConfig — so each secondary adapter connected as the default identity, watched its channels, and resolved its credentials file (#98738). - Add _profile_scoped()/_scoped_platform_setting(): inside a secondary profile scope extra is authoritative and env is not consulted (a missing key fails closed to its default instead of borrowing the default profile's value); single-profile and unscoped/default-profile reads keep the legacy env-over-config precedence. - Apply the scoped read to BuzzAdapter.__init__ (relay, CLI path, channels, home channel, poll interval, require_mention, transport, allowed users), _resolve_private_key (BUZZ_CREDENTIALS_FILE), validate_config, _standalone_send, and check_requirements (which now consults the profile's own config.yaml via the scoped home override). - _env_enablement() returns None inside a profile scope and _apply_yaml_config() skips the env bridge there, so the default profile's env cannot fabricate Buzz for a profile that never configured it and a secondary profile's YAML cannot be pinned into the process env (first-writer-wins, #72348 Telegram/Discord mirror). - Central authorization now consults a plugin platform's live-adapter config.extra.allowed_users (gated on the registry entry declaring allowed_users_env, with an optional normalize_user_id hook so Buzz npub entries match hex-pubkey user ids) — under multiplex only the default profile's list ever reached the env var, so listed secondary-profile users were default-denied (#82871). Empty/absent lists change nothing; default-deny is preserved.