mirror of
https://github.com/AletheiaVox/signal_bridge_remote.git
synced 2026-10-07 03:18:17 +08:00
The 2026-07-27 image rebuild resolved the unpinned '>=' ranges to a new Starlette, which requires python-multipart for all form parsing — and that package was missing from the deployed requirements file. Every OAuth login (POST /oauth/authorize) then failed with a 500. Pin the full server dependency set to the exact versions verified running in production so a rebuild can never silently upgrade the stack again. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
17 lines
612 B
Plaintext
17 lines
612 B
Plaintext
# Signal Bridge Remote — Server Dependencies
|
|
#
|
|
# PINNED on purpose (2026-07-30). An unpinned rebuild on 2026-07-27 silently
|
|
# upgraded Starlette, which broke OAuth form parsing in production
|
|
# (python-multipart was missing from the deployed copy of this file).
|
|
# These are the exact versions verified running together on the droplet.
|
|
# To upgrade: bump deliberately, rebuild, and test the OAuth sign-in flow
|
|
# (GET+POST /oauth/authorize) before walking away.
|
|
fastapi==0.141.1
|
|
starlette==1.3.1
|
|
uvicorn[standard]==0.52.0
|
|
websockets==17.0
|
|
bcrypt==5.0.0
|
|
PyJWT==2.13.0
|
|
python-dotenv==1.2.2
|
|
python-multipart==0.0.32
|