Files
signal_bridge_remote/requirements-server.txt
Aletheia 605f71b742 fix(deps): pin server dependencies, add python-multipart
The 2026-07-27 image rebuild resolved the unpinned '>=' ranges to a new
Starlette, which requires python-multipart for all form parsing — and
that package was missing from the deployed requirements file. Every
OAuth login (POST /oauth/authorize) then failed with a 500.

Pin the full server dependency set to the exact versions verified
running in production so a rebuild can never silently upgrade the
stack again.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-30 12:10:53 +02:00

17 lines
612 B
Plaintext

# Signal Bridge Remote — Server Dependencies
#
# PINNED on purpose (2026-07-30). An unpinned rebuild on 2026-07-27 silently
# upgraded Starlette, which broke OAuth form parsing in production
# (python-multipart was missing from the deployed copy of this file).
# These are the exact versions verified running together on the droplet.
# To upgrade: bump deliberately, rebuild, and test the OAuth sign-in flow
# (GET+POST /oauth/authorize) before walking away.
fastapi==0.141.1
starlette==1.3.1
uvicorn[standard]==0.52.0
websockets==17.0
bcrypt==5.0.0
PyJWT==2.13.0
python-dotenv==1.2.2
python-multipart==0.0.32