50aaa426c1
A user who tapped Always on an approval button gets a pairing-store entry. _is_user_authorized() checked the pairing store BEFORE the allowlist and returned True unconditionally, so a paired-but-not-allowed user permanently bypassed TELEGRAM_ALLOWED_USERS (or equivalent) even after being removed from the allowlist (#23778). Record pairing membership but only honor it in the no-allowlist branch. When an allowlist IS configured, the paired user must appear in the canonical allowed_ids set (the same set that resolves WhatsApp aliases, SimpleX names, group allowlists, and the '*' wildcard), so pairing grants no extra access. Cherry-picked/rebased from #47736 (#23805) by ygd58; membership check rewritten to reuse the existing allowlist logic. Adds regression tests.