Advice on user authentication?
What I'm thinking now is when a user logs in, send the username and pass as plain text (or is there somehow a way to hash in javascript?) via an asynchronous call, then server side perform a hash on the string and compare it to what is stored in the database. If successful, return logged in status to the browser. Then it is assumed that session is authenticated. Are there other considerations to be mindful of?
Or what about using SSL for the initial handshake, and then use normal HTTP once the user has been authenticated? This way the login text is sent securely, but then the SSL connection can be closed to free resources and improve speed. No protection against main-in-the-middle attacks, but that's probably ok.
Security for this is not critical, but probably more so than other projects I've worked on in the past so I would like to have all bases covered. I figured this site was a good place to tap some expert knowledge.