From 605f71b74264da96d2bc53e63750b9751fd93f2e Mon Sep 17 00:00:00 2001 From: Aletheia Date: Thu, 30 Jul 2026 12:10:53 +0200 Subject: [PATCH] fix(deps): pin server dependencies, add python-multipart MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The 2026-07-27 image rebuild resolved the unpinned '>=' ranges to a new Starlette, which requires python-multipart for all form parsing — and that package was missing from the deployed requirements file. Every OAuth login (POST /oauth/authorize) then failed with a 500. Pin the full server dependency set to the exact versions verified running in production so a rebuild can never silently upgrade the stack again. Co-Authored-By: Claude Fable 5 --- requirements-server.txt | 22 +++++++++++++++------- 1 file changed, 15 insertions(+), 7 deletions(-) diff --git a/requirements-server.txt b/requirements-server.txt index f8b73c5..16e4b5d 100644 --- a/requirements-server.txt +++ b/requirements-server.txt @@ -1,8 +1,16 @@ # Signal Bridge Remote — Server Dependencies -fastapi>=0.109.0 -uvicorn[standard]>=0.27.0 -websockets>=12.0 -bcrypt>=4.1.0 -PyJWT>=2.8.0 -python-dotenv>=1.0.0 -python-multipart>=0.0.9 +# +# PINNED on purpose (2026-07-30). An unpinned rebuild on 2026-07-27 silently +# upgraded Starlette, which broke OAuth form parsing in production +# (python-multipart was missing from the deployed copy of this file). +# These are the exact versions verified running together on the droplet. +# To upgrade: bump deliberately, rebuild, and test the OAuth sign-in flow +# (GET+POST /oauth/authorize) before walking away. +fastapi==0.141.1 +starlette==1.3.1 +uvicorn[standard]==0.52.0 +websockets==17.0 +bcrypt==5.0.0 +PyJWT==2.13.0 +python-dotenv==1.2.2 +python-multipart==0.0.32