take two.

Free course · Registered members · Lesson 5 / 10

Authentication, sessions and roles

Implement registration and login, then prove that a reader cannot publish.

45 minutes including practiceAll courses

Editorial team: Take Two · Published

Lesson preview

Authentication and authorisation

Login answers “who are you?”. A role check answers “may you perform this operation?”. The project reads the current role from the database and checks it on /edit and /save. Hiding a button helps the interface, but does not stop a manually constructed request. Registration ignores any role submitted by the form and always creates a member.

Passwords and session lifecycle

The database stores a password_hash result; password_verify checks login. The reference uses Argon2id when available and the PHP default otherwise. It limits passwords to 12–72 bytes so a bcrypt fallback cannot ignore trailing bytes. Login rotates the session ID and CSRF token. Cookies are HttpOnly and SameSite=Lax, Secure on HTTPS; one hour of inactivity requires another login.

What to check as you practise

  • Registration never grants privileged roles.
  • Unauthorised or invalid-token POSTs return 403.
  • Logout uses POST; login rotates the session.

Continue with the full lesson

Register free to access the complete explanation, examples, exercise and commented answer. This preview stays open to everyone.

Workshop files · Version 1

The reference project

Download the complete blog, English and Italian instructions, SQL schema, agent contracts, fictional fixtures and tests. The sample blog interface is in English. This is a local learning project: password recovery, email verification and MFA remain extensions before opening it to a public community.

Download the blog project (ZIP) →

Free download. Full lessons require a free Take Two account. Codex access depends on your own plan.

Sources and further reading