Fix timer action 500s after FastAPI upgrade

FastAPI 0.141 raises when response serialization hits a lazy-load
(current_block.subject.options) in async context, where 0.115 silently
skipped it. Eager-load Subject.options in session get/timer and the TV
dashboard queries. Pin pydantic 2.13.5.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
derekcandClaude Opus 5.5 committed 2026-09-24 23:51:10 -07:00
1 parent 4130467b22
commit 5a2510059d
5 files changed
+10 -4

No files matched your search

+2 -1
View File
@@ -7,7 +7,7 @@ Maintenance release from the 2026-09-24 review (`reports/maintenance-2026-09-24.
### Security
- Rate limits now apply to each client. nginx resolves the real client IP through Cloudflare → NPM (`set_real_ip_from` + `real_ip_recursive`). Before this, every request looked like it came from NPM, so all users shared one login limit.
- ntfy alerts show the real client IP (`X-Real-IP` from nginx). They no longer use the first `X-Forwarded-For` entry, which the client controls.
- Python dependency updates:
- Python dependency updates (pydantic now pinned at 2.13.5):
- PyJWT 2.15.0 (fixes an auth bypass)
- anyio 4.15.1
- fastapi 0.141.1 / starlette 1.7.0
@@ -29,6 +29,7 @@ Maintenance release from the 2026-09-24 review (`reports/maintenance-2026-09-24.
- Docker log rotation on all services: json-file, 10 MB × 3.
### Fixes
- **Timer actions returned 500** after the FastAPI 0.141 upgrade. The session queries didn't load `Subject.options`, which `DailySessionOut` serializes. Old FastAPI silently swallowed the failed lazy-load; the new one raises it. Now eager-loaded in `sessions.py` (get/timer) and `dashboard.py`.
- The meeting alert catch-up window fix (`8e92ae6`) is now deployed.
### Known / accepted