Auth Hardening

Session and Authentication Hardening

A login is only as strong as the session behind it. Sessions and Uploads set the mechanics: the cookie flags Secure, HttpOnly and SameSite (Cookie Attributes), use_strict_mode, and regenerating the ID on every privilege change (Session Fixation). This subsection adds the authentication layer: throttling and re-issuing on login.

auth.php: hardened session start, rate-limited login, ID regenerationPHP
session_start(['cookie_secure' => true, 'cookie_httponly' => true,
    'cookie_samesite' => 'Lax', 'use_strict_mode' => true]);
$HASH = password_hash('s3cret', PASSWORD_DEFAULT);     // the stored hash would come from the DB
$_SESSION['fails'] ??= 0; $_SESSION['lock_until'] ??= 0;
if (time() < $_SESSION['lock_until']) {                // still locked out
    http_response_code(429); exit('locked for ' . ($_SESSION['lock_until'] - time()) . "s\n");
}
if (password_verify($_POST['password'] ?? '', $HASH)) {
    session_regenerate_id(true);                       // new ID on privilege change
    $_SESSION['fails'] = 0; $_SESSION['uid'] = 1;
    exit("login ok, uid={$_SESSION['uid']}\n");
}
if (++$_SESSION['fails'] >= 3) { $_SESSION['lock_until'] = time() + 30; $_SESSION['fails'] = 0; }
http_response_code(401);
echo "login failed (attempt {$_SESSION['fails']})\n";

Four wrong guesses with a shared curl 3,008 cookie jar, then the correct password while locked, then the cookie the server issues (the third failure sets the lock and resets the counter, so it reads attempt 0):

Output of 187
login failed (attempt 1)
login failed (attempt 2)
login failed (attempt 0)
locked for 30s
...
Set-Cookie: PHPSESSID=5c611c9e86625c831543f1ece015bf11; path=/; secure; HttpOnly; SameSite=Lax

After three failures the account backed off for 30 seconds, the correct password was refused while the lock held, and the cookie carries all three protective flags. Beyond this, enforce a strong password policy (length over complexity; reject known-breached passwords), regenerate the ID on logout while clearing $_SESSION (Subsection 4.15.7), keep an idle and an absolute timeout, and re-authenticate before sensitive actions.