And make configurable via an ICP. Provide a reasonable default value,
and use it as a lower bound so user error can't lead to an insecure /
unsustainable amount of hashing.
Aside from being somewhat overdue on account of age (passlib's current
default were last updated 6 years ago), this is also made much more
feasible by API keys, meaning non-interactive use (RPC) is less
strained by the (interactive) password hashing.
Also modernize passlib usage:
* Remove global `DEFAULT_CRYPT_CONTEXT`, create inline (as overhead
should not be too huge given what we're doing with it), and
`ormcache()` for safety, the caches should be invalidated on any ICP
addition, removal, or update, so user update to the rounds
configuration should get reflected immediately.
* Switch on `deprecated=["auto"]`, feature was added in 1.6 and we now
depend on 1.7.
* Remove mentions of `encrypt`, it is deprecated in 1.7.
closesodoo/odoo#81498
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>