Skip to content

Register a user and sign in after success

How-to guide · Intermediate

A registration action with validation, password hashing, a fixed initial role and login after insertion.

Create a new user account and start its session after the account is saved.

Also called: register, signup, sign up, auto login, password hash.

  • A working Database Security Provider and login action from Create a working login form.
  • A users table with a unique username constraint and fields for the account data.
  • This example grants immediate access. A project requiring verification or approval must complete that step before starting an unrestricted session.

Create a separate API action auth/register. Define the submitted username, password and email under Inputs → POST, using required and appropriate format/length validation. The database must enforce a unique username. Do not accept an initial role or account privilege from the public form.

Add Crypto → Password Hash and name it password_hash. Bind Password to $_POST.password and choose the algorithm used by your project’s provider; the current Demo Projects HQ user-creation action uses Argon2id. Keep this step’s Output disabled.

Add Database Insert after hashing. Select the users table. Map username and email from the validated inputs, password from password_hash, and role to the fixed normal-user value for your app. Do not bind role to a client-submitted field. Keep password and hash out of all returned output.

After the insert, add Security Login using the same security provider. Bind Username to the submitted username and Password to the original submitted password so the provider can verify it against the newly stored hash. Do not pass password_hash as the login password. Let failed inserts stop the workflow before this step.

Create a Server Connect Form targeting auth/register, with input Names matching the action. Add request-state feedback and redirect from the form’s Success event after the action completes. Return only the non-sensitive result the page needs, such as the user identity.

Register a new test username. Inspect the database to confirm a hash was stored and the intended role was assigned. Verify the session can access the intended page. Test a duplicate username and invalid input: both should be rejected without creating extra accounts. Finally sign out and sign back in with the new credentials.

One user row is created with a password hash and the fixed initial role. The new user can access the intended signed-in page; a duplicate or invalid registration does not create another account.