You shouldn't be rolling your own authentication. That's just asking for trouble.
I don't have experience with those frameworks, but the rails equivalent, devise, is very good. I assume it's the same for any mature framework.
I don't have experience with those frameworks, but the rails equivalent, devise, is very good. I assume it's the same for any mature framework.
He is not asking for trouble..
One could also use the builtin language functionality and external packages to write custom crypto, and I think we'd both agree that that's a bad idea. I'd argue that it's the same for authentication in general.
I see a frameworks like laraval as the middle path where you can rely on the framework to handle auth but also can make any changes you may need.