Claude 5c555ca7b5 Cache validated access tokens to skip per-request HMAC verify
async_validate_access_token ran a full HMAC-SHA256 signature verify plus
claims validation on every authenticated request, even though the
signature of a given token string never changes. Only the exp claim is
time-dependent.

Cache the (refresh_token_id, exp) of each successfully validated token in
a bounded LRU. On a repeat request the hot path becomes a dict lookup, an
exp comparison and the existing refresh-token lookup, skipping the HMAC
verify entirely.

Security is unchanged:
- Only tokens that pass the full signature/issuer/iat verification are
  ever cached, so a forged token can never enter the cache.
- The refresh token is re-fetched from the store on every call, so a
  revoked or removed token (its refresh token is gone) is still rejected,
  and an inactive user is still rejected.
- The exp claim is rechecked against the same leeway on every cache hit,
  so an expired token is still rejected (and evicted).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PXQwLpKCf8FvhWoSc2Jw61
2026-07-03 21:00:05 +00:00
2026-07-03 06:18:04 -04:00
2026-07-03 06:18:04 -04:00
2026-06-11 22:28:29 +02:00
2026-07-03 06:18:04 -04:00

Home Assistant |Chat Status|
=================================================================================

Open source home automation that puts local control and privacy first. Powered by a worldwide community of tinkerers and DIY enthusiasts. Perfect to run on a Raspberry Pi or a local server.

Check out `home-assistant.io <https://home-assistant.io>`__ for `a
demo <https://demo.home-assistant.io>`__, `installation instructions <https://home-assistant.io/getting-started/>`__,
`tutorials <https://home-assistant.io/getting-started/automation/>`__ and `documentation <https://home-assistant.io/docs/>`__.

|screenshot-states|

Featured integrations
---------------------

|screenshot-integrations|

The system is built using a modular approach so support for other devices or actions can be implemented easily. See also the `section on architecture <https://developers.home-assistant.io/docs/architecture_index/>`__ and the `section on creating your own
components <https://developers.home-assistant.io/docs/creating_component_index/>`__.

If you run into issues while using Home Assistant or during development
of a component, check the `Home Assistant help section <https://home-assistant.io/help/>`__ of our website for further help and information.

|ohf-logo|

.. |Chat Status| image:: https://img.shields.io/discord/330944238910963714.svg
   :target: https://www.home-assistant.io/join-chat/
.. |screenshot-states| image:: https://raw.githubusercontent.com/home-assistant/core/dev/.github/assets/screenshot-states.png
   :target: https://demo.home-assistant.io
.. |screenshot-integrations| image:: https://raw.githubusercontent.com/home-assistant/core/dev/.github/assets/screenshot-integrations.png
   :target: https://home-assistant.io/integrations/
.. |ohf-logo| image:: https://www.openhomefoundation.org/badges/home-assistant.png
   :alt: Home Assistant - A project from the Open Home Foundation
   :target: https://www.openhomefoundation.org/
S
Description
🏡 Open source home automation that puts local control and privacy first.
Readme
2.2 GiB
Languages
Python 100%