Reduce per-request MCP App Password verification cost #516

Open
opened 2026-09-30 13:36:00 +00:00 by kayg · 1 comment
Owner

Parent: Forgejo #492.

The locked #492 profile recorded warm Search Notes tools/call at p50 19.894 ms and p95 23.130 ms, and tools/list at p95 21.051 ms, on a persistent local HTTP/1.1 connection. These are client-side loopback values. The responses had no Server-Timing header, so the server-side p95 target cannot be confirmed or attributed from this run.

The source verifies each Bearer App Password request in crates/calternal-server/src/wire.rs (verify_app_password and record_app_password_use). crates/calternal-auth/src/store.rs reads the password row and verifies its Argon2id hash in spawn_blocking. The MCP tool handler already dispatches directly to the in-process API router via oneshot in crates/calternal-server/src/mcp.rs.

Measure a revoke-aware verification cache for MCP requests. A revoked password must fail on the next request. Add or use server-side timing so the simple-read target below 20 ms can be measured directly. The current profile does not show what share of the loopback latency comes from password verification.

Parent: Forgejo #492. The locked #492 profile recorded warm Search Notes `tools/call` at p50 19.894 ms and p95 23.130 ms, and `tools/list` at p95 21.051 ms, on a persistent local HTTP/1.1 connection. These are client-side loopback values. The responses had no `Server-Timing` header, so the server-side p95 target cannot be confirmed or attributed from this run. The source verifies each Bearer App Password request in `crates/calternal-server/src/wire.rs` (`verify_app_password` and `record_app_password_use`). `crates/calternal-auth/src/store.rs` reads the password row and verifies its Argon2id hash in `spawn_blocking`. The MCP tool handler already dispatches directly to the in-process API router via `oneshot` in `crates/calternal-server/src/mcp.rs`. Measure a revoke-aware verification cache for MCP requests. A revoked password must fail on the next request. Add or use server-side timing so the simple-read target below 20 ms can be measured directly. The current profile does not show what share of the loopback latency comes from password verification.
Author
Owner

Same root cause as #512 (App Password verification per request); one shared, revoke-aware cache fixes both. Tracked in the #512 job.

Same root cause as #512 (App Password verification per request); one shared, revoke-aware cache fixes both. Tracked in the #512 job.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#516
No description provided.