Setting up
Before we jump right into making a user authentication system, there is a lot of setup code. To run any type of authentication, our app will need the following elements common to all:
- First, the user models will need proper password hashing
- Second, a login form and a registration form will be needed to validate user input
- Third, a login view and a registration view with templates for each will be needed
- Fourth, various social logins need to be set up in order to tie them into the login system when it is implemented
Updating the models
Until now, our users had their passwords stored as a plain text in the database. This is a major security flaw. If any malicious user were to gain access to the data in the database, they could log in to any account. The fallout of such a breach would be greater than our site. Large amounts of people on the Internet use a common password for many sites.
If an attacker had access to an e-mail and password combination, it is very likely that this information...