8c58e4f976
A2A_PORT and A2A_ADVERTISED_TOOLSETS are already captured at construction time (inside _profile_runtime_scope) via _get_scoped_secret(), but A2A_PUBLIC_URL was still read with a bare os.getenv() inside A2ARequestHandler._request_public_url() - which runs on ThreadingHTTPServer's per-connection OS thread, not the constructing thread. Raw threading.Thread never inherits contextvars, so even swapping the reader to _get_scoped_secret() at that call site would not help: the request thread has no scope, secret_scope falls back to os.environ either way. The value must be captured once at construction time (which does run in profile scope) and threaded through as instance state instead - same fix shape as A2A_PORT above. A secondary multiplex profile without its own A2A_PUBLIC_URL now falls back to the X-Forwarded-Host/Host-derived URL (or the bind host) instead of silently advertising the default profile's public URL in its Agent Card / discovery response. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> (cherry picked from commit 0c36aca5de53d88bbbc0b4cfceaed8307c744f7a)