Login with sessions

Contents
password_hash and verify
A login sketch
Guard pages
Logout

password_hash and verify

Passwords are never stored as plain text. A hash is a one-way fingerprint: easy to compute, practically impossible to reverse. PHP computes it with password_hash() and checks a login attempt with password_verify() - the function compares, never you.

The second argument is the algorithm. PASSWORD_DEFAULT tracks the current best choice, so hashes stay strong without code changes. Store the full result in one text column - it already carries the algorithm, the cost, and the salt.

$hash = password_hash($password, PASSWORD_DEFAULT); if (password_verify($password, $hash)) { echo "Welcome back"; }

A login sketch

A login script does four things in order: start the session, load the user row by name, verify the password, and only then mark the session as logged in. Anything else - greeting the user, loading settings - waits until after the check.

On success, rotate the session id with session_regenerate_id(true) so an id seen before login cannot be reused after it. Then store the user id and redirect. The full login flow is covered in Authentication and Authorization in PHP 8.

session_start(); if (password_verify($password, $row["hash"])) { session_regenerate_id(true); $_SESSION["user_id"] = (int) $row["id"]; header("Location: /dashboard.php"); exit; }

Guard pages

Every protected page repeats the same two lines: start the session, then demand a logged-in marker. Put the check at the very top, before any output - headers and redirects stop working once the page starts printing.

session_start(); if (!isset($_SESSION["user_id"])) { header("Location: /login.php"); exit; }

Logout

Logout reverses login: empty the session array, destroy the session on the server, and send the user back to the login page. Destroying without emptying, or emptying without destroying, leaves half a session behind - which is how ghost logins happen.

session_start(); $_SESSION = []; session_destroy(); header("Location: /login.php"); exit;

Next: JSON REST endpoint

Article author: Arthur Isaev

Related articles
Development with PHP
PHP course: zero to hero in 50 lessons
What is PHP and where it runs
Install PHP 8.5 and run your first command
Your first PHP script
Comments in PHP
Variables and constants
Types in PHP
Strings in PHP
Numbers in PHP
Operators
if and else
switch and match
Ternary, null coalescing and nullsafe
Loops
Arrays
Associative arrays
Functions
Variable scope
include and require
Namespaces
Composer and autoloading
Everyday string functions
Dates and time
JSON in PHP
Reading and writing files
Errors: read, reproduce, fix
Classes and objects
Constructors and promotion
Inheritance
Interfaces and traits
Enums
Magic methods
Attributes
Exceptions
Strict types
Closures and arrow functions
Generators with yield
Forms: GET and POST
HTTP: headers and status codes
Cookies
Sessions
Login with sessions
JSON REST endpoint
Database with PDO
Uploads and .htaccess
Lint like a pro
Clean functions
Debugging
Modern PHP tour: 5 to 8.4
PHP 8.5 for busy developers
Hero roadmap: the whole course on one page
Install PHP 8.5 on Windows 11
Install PHP 8.5 on Ubuntu
Install PHP 8.5 on Rocky Linux
Install PHP 8.5 on macOS
Install PHP 8.5 on FreeBSD
PHP 8.5 in Docker

Search this site

Channel @aofeed Chat @aofeedchat

Contacts and cooperation:
I recommend our hosting beget.ru
Write to info@urn.su if you:
1. Want to write an article for our site or translate an article into your native language.
2. Want to place thematically relevant ads on the site.
3. Ads on my site pass maximum censorship. If you see an ad block unsuitable for school-age children, shocking or misleading - please contact us by e-mail
4. Found a mistake, inaccuracy, bug, etc. on the site. ... .......
5. Articles can be shared on social media by clicking a network icon: