PHP Login & Authentication System
A complete user authentication solution with registration, login, password reset, email verification, role-based access control, and secure session management. Production-ready and easy to integrate.
Overview
User authentication is a critical component of most web applications, and getting it wrong can have serious security consequences. This script provides a fully tested authentication system that handles every aspect of the user lifecycle from registration through login, password management, and access control.
Passwords are hashed using bcrypt with automatic cost factor adjustment. Sessions are protected against fixation and hijacking attacks. Remember-me tokens use a secure split-token approach. The system includes brute-force protection with account lockout after configurable failed attempts.
Key Features
- User registration with email verification
- Secure login with bcrypt password hashing
- Password reset via email token
- Remember-me with split-token approach
- Account lockout after failed attempts
- Session fixation and hijacking protection
- Role-based access control (admin, editor, user)
- User profile management
- Account activation and deactivation
- Login activity logging
- CSRF protection on all forms
- Optional two-factor authentication (TOTP)
Authentication Flow
The registration flow begins when a user fills in their details. The system validates the input, checks for duplicate emails, hashes the password with bcrypt, creates the user record, and sends a verification email with a time-limited token. Users must click the verification link before they can log in.
During login, the system verifies the email and password, checks for account locks, regenerates the session ID to prevent fixation attacks, and optionally sets a secure remember-me cookie. If two-factor authentication is enabled, the user is prompted for their TOTP code before the session is fully authenticated.
Code Example
Database Schema
The script includes a well-structured MySQL schema with tables for users, roles, permissions, password reset tokens, remember-me tokens, and login activity logs. All tables use InnoDB with proper indexes for fast lookups. Foreign key constraints maintain referential integrity across related tables.
Installation Steps
- Download and extract the script package to your server
- Import
database.sqlinto your MySQL database - Copy
config.example.phptoconfig.phpand fill in your database credentials, SMTP settings, and application URL - Set the
sessions/directory to be writable by the web server - Access
/registerto create your first account - Promote the first user to admin via the database or included CLI tool
Server Requirements
| Requirement | Minimum | Recommended |
|---|---|---|
| PHP Version | 8.0 | 8.2+ |
| Database | MySQL 5.7 | MySQL 8.0+ |
| PHP Extensions | PDO, OpenSSL, mbstring | + intl, gmp (for 2FA) |
| HTTPS | Required | Required |
Security Measures
This authentication system implements multiple layers of security. Passwords are hashed with bcrypt using a cost factor of 12. All database queries use PDO prepared statements. Session cookies are set with HttpOnly, Secure, and SameSite=Lax flags. CSRF tokens protect every form submission. Account lockout activates after five consecutive failed login attempts with exponential backoff. Login attempts are logged with IP address and user agent for audit purposes.