6dec4bfc88
alongside every set_hermes_home_override() call site on the tui_gateway path, and converted session.create, session.resume (both the _make_agent and _init_session scopes), the lazy _build resume and the per-turn submit handler. session.branch was missed. The branch handler already binds the parent's HERMES_HOME and its profile-scoped state.db — its own comment says it mirrors session.create/resume — but builds the branched agent with no secret scope. get_secret() then falls through to process os.environ, which in an app-global/remote backend is the LAUNCH profile's environment: a session branched off profile X authenticates with profile Y's credentials. That is the same cross-profile resolution #67605 fixed for the sibling paths, and it is silent (multiplexing is only activated by the messaging gateway, so the fail-closed UnscopedSecretError path never fires here). Install set_secret_scope(build_profile_secret_scope(parent_home)) for the build and release it in the same finally block as the home override. Salvage-note: code relocated from tui_gateway/server.py to tui_gateway/methods_session.py (session handlers moved after the PR was opened); test patch targets unchanged — HandlerRegistry rebinds handlers onto server.py globals