Skip to main content

final class atoti.CredentialsCacheConfig

The config of the cache of accepted credentials. Checking a password can be slow (the password encoder is memory-hard, e.g. Argon2), so the session remembers the credentials it already accepted instead of checking them again on every request. Only successful checks are cached: a rejected password always runs the full check.

max_count : int = 10000

How many accepted credentials pairs are remembered at once. Once reached, remembering another pair drops the least recently used one. 0 disables the cache.