# Login workflow and example for Expressive 3

**URL:** <https://discourse.laminas.dev/t/login-workflow-and-example-for-expressive-3/600>\
**Category:** Mezzio\
**Tags:** expressive, authentication\
**Created:** [May 29, 2018, 1:45pm UTC](https://discourse.laminas.dev/t/login-workflow-and-example-for-expressive-3/600 "2018-05-29T13:45:10Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![MichaelB](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@MichaelB](https://discourse.laminas.dev/u/MichaelB)\
**Post date:** [May 29, 2018, 1:45pm UTC](https://discourse.laminas.dev/t/login-workflow-and-example-for-expressive-3/600/1 "2018-05-29T13:45:10Z")

</div>

Hi,

I started a new project with Expressive 3. I need authentication with a login page, users in a database, … basic things at this time.

I found only one example of login process that @samsonasik made ([https://samsonasik.wordpress.com/2018/01/12/create-login-functionality-in-expressive-3/](https://samsonasik.wordpress.com/2018/01/12/create-login-functionality-in-expressive-3/)) but i cannot apply all to expressive 3 final version.

It use things like that in handle… $response = $handler-\>handle($request);

Is someone can explain me the flow or have a up to date example that work with the current expressive version?

Thanks!

---

<div class="post-metadata">

**Author:** ![samsonasik](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/samsonasik/32/777_2.png) [@samsonasik](https://discourse.laminas.dev/u/samsonasik)\
**Post date:** [May 29, 2018, 3:52pm UTC](https://discourse.laminas.dev/t/login-workflow-and-example-for-expressive-3/600/2 "2018-05-29T15:52:43Z")

</div>

I’ve updated the post to use latest compatible expressive components.

---

<div class="post-metadata">

**Author:** ![MichaelB](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@MichaelB](https://discourse.laminas.dev/u/MichaelB)\
**Post date:** [May 30, 2018, 6:53am UTC](https://discourse.laminas.dev/t/login-workflow-and-example-for-expressive-3/600/3 "2018-05-30T06:53:07Z")

</div>

Thanks for your update @samsonasik ! But i still have problem (password\_verify in UserRepository /PdoDatabase line 68 return false) and have a question for you…

In the table “users” the password is hashed, so when a user try login, enter his username and password (raw) in the form…

Where is the treatment for “hashing” the password entered to be compared with the hash in the database?

Thanks!

---

<div class="post-metadata">

**Author:** ![froschdesign](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/froschdesign/32/38_2.png) [@froschdesign](https://discourse.laminas.dev/u/froschdesign)\
**Post date:** [May 30, 2018, 7:07am UTC](https://discourse.laminas.dev/t/login-workflow-and-example-for-expressive-3/600/4 "2018-05-30T07:07:20Z")

</div>

> [@MichaelB](#):
>
> Where is the treatment for “hashing” the password entered to be compared with the hash in the database?

In the user repository `Zend\Expressive\Authentication\UserRepository\PdoDatabase`:

> <https://github.com/zendframework/zend-expressive-authentication/blob/master/src/UserRepository/PdoDatabase.php#L85>

See also: [PHP: password\_verify - Manual](http://php.net/manual/en/function.password-verify.php)

---

<div class="post-metadata">

**Author:** ![MichaelB](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@MichaelB](https://discourse.laminas.dev/u/MichaelB)\
**Post date:** [May 30, 2018, 7:30am UTC](https://discourse.laminas.dev/t/login-workflow-and-example-for-expressive-3/600/5 "2018-05-30T07:30:29Z")

</div>

My mistake… i didn’t understood well the password\_verify function… i thought it compare only value…  
I just created a new hash with password\_hash(), add in database and now all is fine for this step!

Thanks @samsonasik and @froschdesign!

---

<div class="post-metadata">

**Author:** ![samsonasik](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/samsonasik/32/777_2.png) [@samsonasik](https://discourse.laminas.dev/u/samsonasik)\
**Post date:** [December 27, 2018, 12:59pm UTC](https://discourse.laminas.dev/t/login-workflow-and-example-for-expressive-3/600/6 "2018-12-27T12:59:24Z")

</div>

I updated my zend expressive blog posts about authentication and authorization with latest zend-expressive-authentication/authorization ^1.0 compatible components:

- [https://samsonasik.wordpress.com/2018/01/12/create-login-functionality-in-expressive-3/](https://samsonasik.wordpress.com/2018/01/12/create-login-functionality-in-expressive-3/)
- [https://samsonasik.wordpress.com/2018/01/13/create-authorization-functionality-in-expressive-3/](https://samsonasik.wordpress.com/2018/01/13/create-authorization-functionality-in-expressive-3/)

---

<div class="post-metadata">

**Author:** ![Laxman\_Thapa](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/laxman_thapa/32/444_2.png) [@Laxman\_Thapa](https://discourse.laminas.dev/u/Laxman_Thapa)\
**Post date:** [February 11, 2019, 9:31pm UTC](https://discourse.laminas.dev/t/login-workflow-and-example-for-expressive-3/600/7 "2019-02-11T21:31:12Z")

</div>

Hi, I am following [https://samsonasik.wordpress.com/2018/01/12/create-login-functionality-in-expressive-3/](https://samsonasik.wordpress.com/2018/01/12/create-login-functionality-in-expressive-3/) for authentication. however I got `Zend \ ServiceManager \ Exception \ ServiceNotCreatedException (2054) Service with name "Zend\Expressive\Authentication\UserRepository\PdoDatabase" could not be created. Reason: SQLSTATE[HY000] [2054] The server requested authentication method unknown to the client`  
screnshot:  
[http://prntscr.com/mfxmkl](http://prntscr.com/mfxmkl)

---

<div class="post-metadata">

**Author:** ![samsonasik](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/samsonasik/32/777_2.png) [@samsonasik](https://discourse.laminas.dev/u/samsonasik)\
**Post date:** [February 16, 2019, 12:43pm UTC](https://discourse.laminas.dev/t/login-workflow-and-example-for-expressive-3/600/8 "2019-02-16T12:43:05Z")

</div>

> [@Laxman\_Thapa](#):
>
> The server requested authentication method unknown to the client

That seems related to your database settings, see [PHP with MySQL 8.0+ error: The server requested authentication method unknown to the client - Stack Overflow](https://stackoverflow.com/questions/52364415/the-server-requested-authentication-method-unknown-to-the-client-php)
