fix(deps): pin server dependencies, add python-multipart

The 2026-07-27 image rebuild resolved the unpinned '>=' ranges to a new
Starlette, which requires python-multipart for all form parsing — and
that package was missing from the deployed requirements file. Every
OAuth login (POST /oauth/authorize) then failed with a 500.

Pin the full server dependency set to the exact versions verified
running in production so a rebuild can never silently upgrade the
stack again.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Aletheia
2026-07-30 12:10:53 +02:00
parent 63d7176ee6
commit 605f71b742

View File

@@ -1,8 +1,16 @@
# Signal Bridge Remote — Server Dependencies # Signal Bridge Remote — Server Dependencies
fastapi>=0.109.0 #
uvicorn[standard]>=0.27.0 # PINNED on purpose (2026-07-30). An unpinned rebuild on 2026-07-27 silently
websockets>=12.0 # upgraded Starlette, which broke OAuth form parsing in production
bcrypt>=4.1.0 # (python-multipart was missing from the deployed copy of this file).
PyJWT>=2.8.0 # These are the exact versions verified running together on the droplet.
python-dotenv>=1.0.0 # To upgrade: bump deliberately, rebuild, and test the OAuth sign-in flow
python-multipart>=0.0.9 # (GET+POST /oauth/authorize) before walking away.
fastapi==0.141.1
starlette==1.3.1
uvicorn[standard]==0.52.0
websockets==17.0
bcrypt==5.0.0
PyJWT==2.13.0
python-dotenv==1.2.2
python-multipart==0.0.32