I’m using the PRG pattern to avoid multiple form submission. It has, however, a serious drawback — you cannot simply echo the confirmation message to the user (
echo
Pretty much every website that allows users to log in does so by relying on a cookie. It ain't a perfect solution, but it's the best we got.
Also session handling is one of those things that a web development framework typically takes care of for you.