OpenClaw's Long-Running Gateway: Continuity Does Not Mean One Shared Session
Suppose one company runs two Telegram bots: one serves European customers, one serves American customers. Both bots hand messages to the same support agent, and the session isolation policy is set to per-channel-peer. One platform user ID happens to appear in both accounts. The system generates the same key: agent:support:telegram:direct:tg:12345 A conversation from the European inbox can then surface in the American inbox’s context. No model jailbreak, no database corruption, no random routing. The system worked exactly as configured — the session key simply lacked the accountId dimension. ...





