Issue #3608417: Add opt-in cached-session drupalLogin() for class-stable accounts

Adds an opt-in drupalLoginCached() to AuthTrait — a process-lifetime cache of authenticated session cookies keyed by uid — so a test class that logs the SAME stable account in every method performs one real login per process instead of one per method. drupalLogin() is unchanged (purely additive).

Mechanism

  • MISS: performs the real drupalLogin() and caches the resulting session cookie keyed by uid.
  • HIT: re-hydrates the Mink session from the cached cookie and confirms it with one cheap GET of /user; a static counter of real logins stays flat, so a hit is provably login-free.
  • STALE/POISONED: a dead cached cookie is evicted and transparently falls back to a real login.

Strictly opt-in; not for tests that exercise the login/auth/TFA flow itself, and it only wins for a stable account reused across a class methods.

Testing

Exercised downstream with a behavior test covering all three paths (miss caches, hit performs zero additional real logins while /user still renders the account, poisoned cookie falls back). Measured ~82% wall-clock reduction on a login-heavy ExistingSite class (12 real logins collapsed to 1).

AI-assistance disclosure

This contribution was drafted with AI assistance (Claude) and reviewed and tested by the contributor before submission, per the drupal.org policy on the use of AI when contributing to Drupal: https://www.drupal.org/docs/develop/issues/issue-procedures-and-etiquette/policy-on-the-use-of-ai-when-contributing-to-drupal

Merge request reports

Loading
Loading