What are the best practices for handling password authentication and hashing in a PHP login system?

When handling password authentication in a PHP login system, it is important to securely hash passwords using a strong hashing algorithm such as bcrypt. This helps protect user passwords in case of a data breach. Additionally, using prepared statements with parameterized queries can help prevent SQL injection attacks.

// Hashing the password before storing it in the database
$password = $_POST['password'];
$hashed_password = password_hash($password, PASSWORD_BCRYPT);

// Verifying the password during login
$username = $_POST['username'];
$password = $_POST['password'];

// Retrieve the hashed password from the database based on the username
// Verify the password using password_verify function
if (password_verify($password, $hashed_password)) {
    // Password is correct, proceed with login
} else {
    // Password is incorrect, display error message
}