DEV Community

Discussion on: QuickAuthPHP – One script for web authentication. Multi-user. No database required.

Collapse
 
exadra37 profile image
Paulo Renato

Bear in mind that what I am gonna say is not a personal attack to the developer and author of this post.

Please don't use this type of approach if you take security seriously and you don't want to have a huge GDPR fine for a data breach of your users Personal Identifiable Information(PII).

Authenticating users must be done by following OWASP recommendations.

I strongly recommend the use of OAUTH 2.0 and OpendID for authenticating a user and lots of battled tested packages exist to provide this functionality.

Collapse
 
llagerlof profile image
Lawrence Lagerlof

Listen to this guy.