FreeIntermediatePHP 8.0+v3.1

PHP Login & Authentication System

A complete user authentication solution with registration, login, password reset, email verification, role-based access control, and secure session management. Production-ready and easy to integrate.

Overview

User authentication is a critical component of most web applications, and getting it wrong can have serious security consequences. This script provides a fully tested authentication system that handles every aspect of the user lifecycle from registration through login, password management, and access control.

Passwords are hashed using bcrypt with automatic cost factor adjustment. Sessions are protected against fixation and hijacking attacks. Remember-me tokens use a secure split-token approach. The system includes brute-force protection with account lockout after configurable failed attempts.

Key Features

  • User registration with email verification
  • Secure login with bcrypt password hashing
  • Password reset via email token
  • Remember-me with split-token approach
  • Account lockout after failed attempts
  • Session fixation and hijacking protection
  • Role-based access control (admin, editor, user)
  • User profile management
  • Account activation and deactivation
  • Login activity logging
  • CSRF protection on all forms
  • Optional two-factor authentication (TOTP)

Authentication Flow

The registration flow begins when a user fills in their details. The system validates the input, checks for duplicate emails, hashes the password with bcrypt, creates the user record, and sends a verification email with a time-limited token. Users must click the verification link before they can log in.

During login, the system verifies the email and password, checks for account locks, regenerates the session ID to prevent fixation attacks, and optionally sets a secure remember-me cookie. If two-factor authentication is enabled, the user is prompted for their TOTP code before the session is fully authenticated.

Code Example

// Secure password verification function authenticateUser($email, $password): ?array { $stmt = $pdo->prepare( 'SELECT * FROM users WHERE email = ?' ); $stmt->execute([$email]); $user = $stmt->fetch(); if ($user && password_verify($password, $user['password_hash'])) { // Rehash if cost factor has changed if (password_needs_rehash($user['password_hash'], PASSWORD_BCRYPT)) { $newHash = password_hash($password, PASSWORD_BCRYPT); // Update stored hash... } return $user; } return null; }

Database Schema

The script includes a well-structured MySQL schema with tables for users, roles, permissions, password reset tokens, remember-me tokens, and login activity logs. All tables use InnoDB with proper indexes for fast lookups. Foreign key constraints maintain referential integrity across related tables.

Installation Steps

  1. Download and extract the script package to your server
  2. Import database.sql into your MySQL database
  3. Copy config.example.php to config.php and fill in your database credentials, SMTP settings, and application URL
  4. Set the sessions/ directory to be writable by the web server
  5. Access /register to create your first account
  6. Promote the first user to admin via the database or included CLI tool

Server Requirements

RequirementMinimumRecommended
PHP Version8.08.2+
DatabaseMySQL 5.7MySQL 8.0+
PHP ExtensionsPDO, OpenSSL, mbstring+ intl, gmp (for 2FA)
HTTPSRequiredRequired

Security Measures

This authentication system implements multiple layers of security. Passwords are hashed with bcrypt using a cost factor of 12. All database queries use PDO prepared statements. Session cookies are set with HttpOnly, Secure, and SameSite=Lax flags. CSRF tokens protect every form submission. Account lockout activates after five consecutive failed login attempts with exponential backoff. Login attempts are logged with IP address and user agent for audit purposes.