e253ea0233
Under gateway.multiplex_profiles, os.environ holds the DEFAULT profile's values and a secondary profile's .env exists only in its secret scope. Matrix, Home Assistant, Teams, DingTalk, SMS and Telegram already read their *secret* scope-aware, but read the paired endpoint/identity raw from os.environ — so a secondary's token/secret/password was paired with the default profile's host or app identity: - Matrix: MATRIX_HOMESERVER / MATRIX_USER_ID / MATRIX_DEVICE_ID in __init__ and MATRIX_HOMESERVER in _standalone_send -> the secondary's access token was sent to the default's homeserver (and its E2EE device id reused). - Home Assistant: HASS_URL in __init__ and _standalone_send -> the secondary's HASS_TOKEN was posted to the default's HA instance. - Teams: TEAMS_CLIENT_ID / TEAMS_TENANT_ID (env-first, even over extra), TEAMS_SERVICE_URL, TEAMS_HOME_CHANNEL(_NAME) in _credentials, _env_enablement, _standalone_send and __init__ -> Bot Framework token requested for the default's app with the secondary's secret; cron home channel was the default's conversation. - DingTalk: DINGTALK_CLIENT_ID in _credentials, DINGTALK_WEBHOOK_URL in _standalone_send -> wrong app id; cron output posted to the default's robot webhook (URL carries its access_token). - Telegram: TELEGRAM_WEBHOOK_URL in connect() -> the default's public webhook URL registered on the secondary bot, mixing update traffic. Each read now goes through the same scoped reader its sibling secret already uses (_get_scoped_secret / _startup_env_secret / get_secret with the UnscopedSecretError fallback), so a scoped miss is empty rather than the default profile's value; the unscoped default-profile path and single-profile deployments keep reading os.environ, which there IS the profile's own value. Teams _credentials now lets extra (per-profile config.yaml) win over env, matching every other adapter and its own __init__. Live repro (/tmp/mux_audit/fix-endpoint-identity/repro.py, secondary scope "bot2" with the default profile in os.environ): 19 of 24 reads returned the default's endpoint/identity before; 0 after. Salvage: SMS from-number fix cherry-picked from #100625 (tests trimmed to two invariants). Teams identity (#100622) and DingTalk (#100615) reimplemented on the minimal shape — the Teams PR added a _profile_scoped() gate to _env_enablement and the DingTalk PR only covered the YAML bridge, not DINGTALK_CLIENT_ID / DINGTALK_WEBHOOK_URL. Matrix, Home Assistant and Telegram parts have no prior PR. Co-authored-by: nftpoetrist <264138787+nftpoetrist@users.noreply.github.com>