mirror of
https://github.com/home-assistant/core.git
synced 2026-08-28 02:24:46 -05:00
claude/auth-token-verify-cache
async_validate_access_token ran a full HMAC-SHA256 signature verify plus claims validation on every authenticated request, even though the signature of a given token string never changes. Only the exp claim is time-dependent. Cache the (refresh_token_id, exp) of each successfully validated token in a bounded LRU. On a repeat request the hot path becomes a dict lookup, an exp comparison and the existing refresh-token lookup, skipping the HMAC verify entirely. Security is unchanged: - Only tokens that pass the full signature/issuer/iat verification are ever cached, so a forged token can never enter the cache. - The refresh token is re-fetched from the store on every call, so a revoked or removed token (its refresh token is gone) is still rejected, and an inactive user is still rejected. - The exp claim is rechecked against the same leeway on every cache hit, so an expired token is still rejected (and evicted). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PXQwLpKCf8FvhWoSc2Jw61
…
…
…
…
Home Assistant |Chat Status| ================================================================================= Open source home automation that puts local control and privacy first. Powered by a worldwide community of tinkerers and DIY enthusiasts. Perfect to run on a Raspberry Pi or a local server. Check out `home-assistant.io <https://home-assistant.io>`__ for `a demo <https://demo.home-assistant.io>`__, `installation instructions <https://home-assistant.io/getting-started/>`__, `tutorials <https://home-assistant.io/getting-started/automation/>`__ and `documentation <https://home-assistant.io/docs/>`__. |screenshot-states| Featured integrations --------------------- |screenshot-integrations| The system is built using a modular approach so support for other devices or actions can be implemented easily. See also the `section on architecture <https://developers.home-assistant.io/docs/architecture_index/>`__ and the `section on creating your own components <https://developers.home-assistant.io/docs/creating_component_index/>`__. If you run into issues while using Home Assistant or during development of a component, check the `Home Assistant help section <https://home-assistant.io/help/>`__ of our website for further help and information. |ohf-logo| .. |Chat Status| image:: https://img.shields.io/discord/330944238910963714.svg :target: https://www.home-assistant.io/join-chat/ .. |screenshot-states| image:: https://raw.githubusercontent.com/home-assistant/core/dev/.github/assets/screenshot-states.png :target: https://demo.home-assistant.io .. |screenshot-integrations| image:: https://raw.githubusercontent.com/home-assistant/core/dev/.github/assets/screenshot-integrations.png :target: https://home-assistant.io/integrations/ .. |ohf-logo| image:: https://www.openhomefoundation.org/badges/home-assistant.png :alt: Home Assistant - A project from the Open Home Foundation :target: https://www.openhomefoundation.org/
Languages
Python
100%