- /m (or /menu) opens a card menu; /sessionlist and /workspacelist render
cards with bind/switch buttons; number replies stay usable as a fallback
when the app does not subscribe card.action.trigger.
- card.action.trigger callbacks validate the operator's open_id against the
allowed senders: group members outside the allowlist can never drive
binding, workspace switches or other card actions.
- Session-list pagination uses page numbers everywhere (buttons carry
sessions:<page>), fixing the previous double page-size scaling that
skipped pages past 20 sessions.
- Bind/workspace failures map to safe user-facing messages instead of raw
error details.
- Apps registered after this change subscribe card.action.trigger during
the scan flow.