Rolling his own doesn't mean custom algos. It means he will use the buildin language functions and/or external packages for that functionality while manually piping all of the pieces together.
He is not asking for trouble..
He is not asking for trouble..
One could also use the builtin language functionality and external packages to write custom crypto, and I think we'd both agree that that's a bad idea. I'd argue that it's the same for authentication in general.
I see a frameworks like laraval as the middle path where you can rely on the framework to handle auth but also can make any changes you may need.