Building a small side project, a shared expense tracker for splitting bills among a group of friends, and I have hit the point where I genuinely need proper user accounts and login functionality, something I have honestly avoided dealing with directly in every previous smaller project by either skipping accounts entirely or just hardcoding a single fake user for my own personal testing purposes only.
Looked into building authentication myself from scratch initially just to properly understand it, and quickly realized there is considerably more involved than I originally expected, properly hashing passwords securely, handling password reset flows safely, session or token management that actually works correctly and securely across page reloads, and a genuinely long list of smaller security considerations I honestly had never even thought about seriously before actually researching this specific topic myself in any real depth.
Ended up looking into a few managed authentication services instead rather than continuing to build everything entirely from scratch myself, which feels like the more sensible and practical approach for a smaller side project like this one, though I am still trying to properly understand the actual tradeoffs between the handful of specific options I have found so far during my research on this.
A developer friend mentioned that rolling your own authentication system completely from scratch is generally considered a genuinely bad idea for most smaller projects specifically, mainly because of exactly how many subtle security details are actually easy to get wrong without even realizing it at the time, which lines up closely with what I have been independently discovering myself through this whole research process so far.
For anyone who has actually built a similarly sized side project recently themselves, what did you personally end up using specifically for authentication, and would you genuinely recommend that same specific option again if starting an entirely new project today?