How to improve my user login scheme
问题 Question is easy and basic. I've been working with PHP sessions for years and I always managed user login/logout this way: Start session ( session_start() call). Login: Store a value in the session (i.e. $_SESSION["user_id"] = 34 ). Check user logged: Check session value (i.e. isset($_SESSION["user_id"]) ). Logout: destroy session ( session_destroy() call and unset($_SESSION["user_id"]) ). This scheme has worked for me with very easy applications, but now I'm working in a bigger application