I'm currently thinking of adding a login system for a website, but I'm a bit hesitant on doing it because of a few security flaws I'm not sure how to solve:
- How would you prevent someone from making a script that spams registries for new accounts?
- Would spam logging in / out stress the DB(mysql) if someone wanted to try to slow down the website?
- Is it recommended to even make my own login system?
My main concern is basically how to prevent malicious bad actors from trying to slow down the website, although I know there are other things I should be looking to prevent. Any insights/best practices are welcome ,as a scavenge of the web didn't lead me to any super useful resources on these topics.