The 2026-07-27 image rebuild resolved the unpinned '>=' ranges to a new
Starlette, which requires python-multipart for all form parsing — and
that package was missing from the deployed requirements file. Every
OAuth login (POST /oauth/authorize) then failed with a 500.
Pin the full server dependency set to the exact versions verified
running in production so a rebuild can never silently upgrade the
stack again.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Ported from the Android edition's server:
- Add python-multipart: the OAuth endpoints parse credentials with
request.form(), and Starlette needs this package when a client POSTs
the token request as multipart/form-data. Without it those requests
500'd ('the small auth bug').
- governor_enabled now round-trips SQLite's 0/1 as JSON true/false on
read and normalises any truthy input to 0/1 on write. Strict clients
(kotlinx-serialization) reject anything else.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>