3 Commits

Author SHA1 Message Date
Aletheia
605f71b742 fix(deps): pin server dependencies, add python-multipart
The 2026-07-27 image rebuild resolved the unpinned '>=' ranges to a new
Starlette, which requires python-multipart for all form parsing — and
that package was missing from the deployed requirements file. Every
OAuth login (POST /oauth/authorize) then failed with a 500.

Pin the full server dependency set to the exact versions verified
running in production so a rebuild can never silently upgrade the
stack again.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-30 12:10:53 +02:00
Aletheia
263e6e9b75 fix: OAuth token endpoint multipart support + governor_enabled bool round-trip
Ported from the Android edition's server:

- Add python-multipart: the OAuth endpoints parse credentials with
  request.form(), and Starlette needs this package when a client POSTs
  the token request as multipart/form-data. Without it those requests
  500'd ('the small auth bug').
- governor_enabled now round-trips SQLite's 0/1 as JSON true/false on
  read and normalises any truthy input to 0/1 on write. Strict clients
  (kotlinx-serialization) reject anything else.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 20:06:55 +02:00
Aletheia
142e83d512 Add files via upload 2026-03-14 19:40:48 +01:00