Free course · Registered members · Lesson 5 / 10
Authentication, sessions and roles
Implement registration and login, then prove that a reader cannot publish.
Editorial team: Take Two · Published
Lesson preview
Authentication and authorisation
Login answers “who are you?”. A role check answers “may you perform this operation?”. The project reads the current role from the database and checks it on /edit and /save. Hiding a button helps the interface, but does not stop a manually constructed request. Registration ignores any role submitted by the form and always creates a member.
Passwords and session lifecycle
The database stores a password_hash result; password_verify checks login. The reference uses Argon2id when available and the PHP default otherwise. It limits passwords to 12–72 bytes so a bcrypt fallback cannot ignore trailing bytes. Login rotates the session ID and CSRF token. Cookies are HttpOnly and SameSite=Lax, Secure on HTTPS; one hour of inactivity requires another login.
What to check as you practise
- Registration never grants privileged roles.
- Unauthorised or invalid-token POSTs return 403.
- Logout uses POST; login rotates the session.
Continue with the full lesson
Register free to access the complete explanation, examples, exercise and commented answer. This preview stays open to everyone.
Workshop files · Version 1
The reference project
Download the complete blog, English and Italian instructions, SQL schema, agent contracts, fictional fixtures and tests. The sample blog interface is in English. This is a local learning project: password recovery, email verification and MFA remain extensions before opening it to a public community.
Free download. Full lessons require a free Take Two account. Codex access depends on your own plan.
Sources and further reading
- OpenAI · Codex CLI: setup and first task ↗
- OpenAI · Project instructions with AGENTS.md ↗
- OpenAI · Subagents and coordination ↗
- OpenAI · Non-interactive mode and structured output ↗
- Bootstrap · Getting started ↗
- Bootstrap · JavaScript and jQuery ↗
- jQuery · Official downloads ↗
- PHP · Password hashing ↗
- PHP · PDO prepared statements ↗
- PHP · Session security ↗
- OWASP · CSRF prevention ↗
- Turismo Roma · Roma Live calendar ↗
- Turismo Roma · Crawl rules ↗