QuickAuth covers signup, login, protected routes, and user profiles without a hosted provider like Auth0 or Clerk. Passwords are hashed with Argon2id, and sessions are hashed, stored in the database, and only ever sent in HTTP-only cookies. ClinicScreen uses it for all of its sign-ins.
What I built
- Signup, login, protected routes, and user profiles
- Password hashing with Argon2id
- Sessions that are hashed, stored in the database, and only sent in HTTP-only cookies
- A Prisma schema (User, Profile, Session) that supports checking sessions on the server, expiry, revocation, and disabling accounts