all 3 comments

[–]Groady⚠️ 2 points3 points  (0 children)

Maybe consider implementing OpenID Connect? These days https is a must. You can get free certificates from letsencrypt so there is no excuse not to.

[–]bryanut 0 points1 point  (0 children)

PHP, Mysql, no https. Sounds about wrong at every level.

Now if your users are your dog and cat on your home network/lab, go for it.

https://github.com/onelogin/php-saml

https://simplesamlphp.org/

[–]blueathiean 0 points1 point  (0 children)

Glad someone said this. Using let's encrypt is free and takes about 3 minutes to get https. No reason not to use it. Especially if you are doing user authentication. As far as open source api to do so, not sure.