Register a user and sign in after success
A registration action with validation, password hashing, a fixed initial role and login after insertion.
Create a new user account and start its session after the account is saved.
Also called: register, signup, sign up, auto login, password hash.
Before you begin
Section titled “Before you begin”- A working Database Security Provider and login action from Create a working login form.
- A users table with a unique username constraint and fields for the account data.
- This example grants immediate access. A project requiring verification or approval must complete that step before starting an unrestricted session.
Define and validate registration inputs
Section titled “Define and validate registration inputs”Create a separate API action auth/register. Define the submitted username, password and email under Inputs → POST, using required and appropriate format/length validation. The database must enforce a unique username. Do not accept an initial role or account privilege from the public form.
Hash the submitted password
Section titled “Hash the submitted password”Add Crypto → Password Hash and name it password_hash. Bind Password to $_POST.password and choose the algorithm used by your project’s provider; the current Demo Projects HQ user-creation action uses Argon2id. Keep this step’s Output disabled.
Insert the user with a fixed initial role
Section titled “Insert the user with a fixed initial role”Add Database Insert after hashing. Select the users table. Map username and email from the validated inputs, password from password_hash, and role to the fixed normal-user value for your app. Do not bind role to a client-submitted field. Keep password and hash out of all returned output.
Log in only after the insert succeeds
Section titled “Log in only after the insert succeeds”After the insert, add Security Login using the same security provider. Bind Username to the submitted username and Password to the original submitted password so the provider can verify it against the newly stored hash. Do not pass password_hash as the login password. Let failed inserts stop the workflow before this step.
Connect the registration form
Section titled “Connect the registration form”Create a Server Connect Form targeting auth/register, with input Names matching the action. Add request-state feedback and redirect from the form’s Success event after the action completes. Return only the non-sensitive result the page needs, such as the user identity.
Verify the complete account lifecycle
Section titled “Verify the complete account lifecycle”Register a new test username. Inspect the database to confirm a hash was stored and the intended role was assigned. Verify the session can access the intended page. Test a duplicate username and invalid input: both should be rejected without creating extra accounts. Finally sign out and sign back in with the new credentials.
Check your result
Section titled “Check your result”One user row is created with a password hash and the fixed initial role. The new user can access the intended signed-in page; a duplicate or invalid registration does not create another account.