what I would have naturally done without anticipating any flaw (and probably be just OK):
cache_key = sha(sha(id + username) + bcrypt(pass))
with sha256 or something.