identity-management
What a login system has to provide, how pages become available or not per user, the real threat model, and roll-your-own vs. federated vs. hosted identity.
read → new 02A simple, secure PHP + MariaDB signup/login/logout system: bcrypt, CSRF tokens, session cookies, rate limiting, password reset, and per-page role gating.
read → new 03Passwordless sign-in with WebAuthn: registering a passkey, conditional-UI autofill for near-invisible logins, and a fallback plan for devices that don't support it.
read → new 04Authorizing machine clients instead of browsers: API keys vs. bearer tokens vs. OAuth client-credentials, scoping, and rotation.
read → new