WB
WYSIWYG Web Builder 21.0
Native Login Architecture & Implementation Session Log
Turn 1 Login Tools & Architecture Discovery
U
User 2026-10-03 09:12:00
Explain the built-in Login tools of WYSIWYG Web Builder based on MCP information
A
Antigravity DeepMind Advanced Agentic Coding 2026-10-03 09:18:25

Based on the MCP schemas, object definitions, and underlying implementation in WYSIWYG Web Builder, the software provides an extensive, production-ready Login & User Management System MCP namespace login*).

It is designed to secure PHP-based websites without writing server-side code manually, handling everything from authentication and role-based page protection to email verification, OAuth social logins, and administrative dashboards.


1. Core Architecture & Security Foundation

Architecture Diagram (Interactive Flowchart)
flowchart TD
    subgraph Storage ["Storage Layer"]
        DB1["Flat-File (usersdb.php)"]
        DB2["MySQL Database (USERS Table)"]
        DB3["Built-in Users (JSON / Project)"]
    end

    subgraph Auth ["Authentication & Lifecycle"]
        Signup["loginSignup
(Registration & Verification)"] Login["loginLogin / loginSocialLogin
(Authentication Gate)"] Recovery["loginPasswordRecovery
(Token Reset via Mail/SMTP)"] end subgraph Routing ["Access Control & Routing"] Redirect["loginUserRedirect
(Role/User Dispatcher)"] Protect["loginProtectPage
(Session & Role Validator)"] Single["loginSinglePage
(Inline Page Barrier)"] end subgraph UserArea ["User Experience & Self-Service"] Greeting["loginLoginName
(Username / Avatar)"] Edit["loginEditProfile
(Update Profile / Avatar)"] Pass["loginChangePassword
(Update Password)"] Del["loginDeleteProfile
(Self-Delete Account)"] Logout["loginLogout
(Session Termination)"] end subgraph AdminArea ["Administration"] Admin["loginAdmin
(User Management Console)"] end Signup --> Storage Login --> Storage Storage --> Auth Auth --> Routing Routing --> Protect Protect --> UserArea Storage <--> Admin

Dual Backend Modalities

  1. Flat-File Database (usersdb.php):
  2. Stores users in an encrypted, PHP-protected flat text/CSV file directly on the web server.
  3. Requires zero MySQL configuration; works on virtually any basic PHP shared host.
  4. MySQL Database (USERS table):
  5. High-performance relational backend for sites with larger user bases.
  6. Automatically initializes and queries tables: username, password, email, fullname, active, role, avatar, and custom profile fields.
  7. Supports optional access logging to USERS_LOG or CSV.
  8. Built-in Users List (login.database.users.json):
  9. Static users defined in the project file, useful for simple password-protected client areas.

Session & Security Engine

  • Session Management: Automatically emits $PHPSESSION$, tracking $_SESSION['username'], $_SESSION['fullname'], $_SESSION['role'], and $_SESSION['avatar'].
  • Sliding Session Expiration: Enforces session timeouts (login.sessionTimeout, default 600 seconds) and automatically invalidates abandoned sessions.
  • Referrer Memory ($_SESSION['referrer']): When an unauthenticated visitor hits a protected page, it preserves the original URL ($_SERVER['REQUEST_URI']) so they are seamlessly routed back upon successful login.
  • Password Hashing: Configurable hashing supporting PHP password_hash() (Bcrypt/Argon2), SHA, and MD5.

2. Comprehensive Tool Catalog (13 Built-in Objects)

A. Authentication & Sign-In

ToolMCP TypeDescription & Capabilities
Login FormloginLoginThe primary authentication form. Supports username or email address sign-in (allowEmailAddressLogin), password input, "Remember Me" persistent cookie, custom error pages, and direct or referrer-based redirection.
Single Page BarrierloginSinglePageAn inline password barrier placed directly on a page. If unauthenticated, it presents an inline password challenge; once authorized, it reveals page content without navigating away.
Social LoginloginSocialLoginOAuth 2.0 / OpenID Connect integration powered by Hybridauth (hybridauth/autoload.php). Authenticates with providers like Google, Facebook, Twitter, and LinkedIn, auto-provisioning the user into the database and assigning default roles.
LogoutloginLogoutConfigurable logout button or link with FontAwesome icon support. Cleanly unsets all $_SESSION credentials and redirects to a public landing page.

B. Access Control & Page Protection

ToolMCP TypeDescription & Capabilities
Protect PageloginProtectPageAn invisible controller placed at the top of protected pages. Emits early PHP header guards: checks session validity, verifies sliding timeout, checks authorized user lists, verifies User Roles (e.g. [admin], [editor], [member]), and bounces unauthorized traffic to Access Denied Page.
User RedirectloginUserRedirectA smart role-based dispatcher. After login, inspects $_SESSION['role'] (syntax [role]) or specific usernames and routes users to customized portals (e.g. [admin] → admin.php, [vip] → premium.php).

C. Registration & Account Lifecycle

ToolMCP TypeDescription & Capabilities
Sign Up FormloginSignupFull-featured user registration form with username availability checking, password strength regex matching, password confirmation, Captcha verification (reCAPTCHA, hCaptcha, simple math), avatar upload, and custom profile fields.
Account ActivationEmbedded in loginSignupSupports 3 activation modes: Immediate, Email verification link (tokenized activation link sent to user), or Manual Administrator Approval.
Password RecoveryloginPasswordRecoveryHandles forgotten passwords. Generates cryptographically secure one-time tokens and dispatches reset links or temporary credentials via PHP mail(), custom SMTP, or PHPMailer with SSL/TLS.
Change PasswordloginChangePasswordAuthenticated self-service form requiring the user to supply their current password before saving a validated new password.

D. Profile Management & User Context

ToolMCP TypeDescription & Capabilities
Login Name / Profile GreetingloginLoginNameContext-aware dynamic display widget. Injects $_SESSION['username'], $_SESSION['fullname'], or the user's avatar (<img src="<?php echo $_SESSION['avatar']; ?>">). Can also query database stats to show total registered members or the newest member.
Edit ProfileloginEditProfileSubclassed from loginSignup. Automatically prefills with the logged-in user's data and allows them to update their full name, email, avatar, and custom profile attributes.
Delete ProfileloginDeleteProfileSelf-service account deletion for privacy and GDPR compliance. Confirms with the user, purges their database record, unsets session tokens, and redirects them to a goodbye page.

E. Administration & Management

ToolMCP TypeDescription & Capabilities
User AdministratorloginAdminWeb-based management portal. Protected by a dedicated admin password, it allows administrators to search, filter, paginate, manually create, edit, activate/deactivate accounts, and assign user roles without touching phpMyAdmin or the database directly.

3. Comparing the 3 Storage Modes

CapabilityBuilt-in UsersFlat-File (usersdb.php)MySQL Database
Setup ComplexityZero (Design-time)None (Creates file on upload)Requires DB host, user, password
Self-Registration (loginSignup)✕ No✓ Yes✓ Yes
Email Verification✕ No✓ Yes✓ Yes
User Roles & PermissionsBasic✓ Yes✅ Full relational support
Avatar & File Uploads✕ No⚠ Limited✅ Full support
Social OAuth Logins✕ No✕ No✅ Full Hybridauth support
Web Admin Panel (loginAdmin)✕ No✓ Yes✓ Yes (Paginated & searchable)
Best ForStatic client previewSimple blogs & micro-sitesEnterprise apps, SaaS, community portals

4. Standard Implementation Workflow

A standard member portal implementation in WYSIWYG Web Builder typically utilizes 5 core pages:

  1. login.php (Public):
  2. Houses loginLogin and loginSocialLogin.
  3. Links to signup.php and recover.php.
  4. Configured with Destination Page: redirect.php and useReferrer: true.
  5. signup.php (Public):
  6. Contains loginSignup with Captcha enabled and Account Activation: Email Verification.
  7. On submission, user receives an email pointing to activate.php.
  8. redirect.php (Protected Dispatcher):
  9. Invisible routing page containing loginUserRedirect.
  10. Evaluates roles: [admin] → admin.php, [subscriber] → members.php.
  11. members.php (Protected Content Area):
  12. Top of page: loginProtectPage configured to require valid session and allowed roles.
  13. Header area: loginLoginName (displays avatar + "Welcome, John!"), and loginLogout.
  14. Profile tab: loginEditProfile and loginChangePassword.
  15. admin.php (Protected Management Portal):
  16. Top of page: loginProtectPage configured for role [admin].
  17. Body: loginAdmin for user search, activation approval, and role assignments.
Turn 2 Zero Custom HTML/CSS Demo Site Implementation
U
User 2026-10-03 09:34:20
Create a demo website using the login tools do not use cusom HTML/CSS
A
Antigravity DeepMind Advanced Agentic Coding 2026-10-03 09:44:40

The demo website has been built using the native Login Tools in WYSIWYG Web Builder, strictly without any custom HTML or CSS objects.


Project Architecture Overview

PageURLPurposeKey Native WWB Objects Used
Portal Overviewindex.phpPublic landing page explaining features & testing stepsLayoutGrid, Heading, Text, Button
Member Sign Inlogin.phpAuthentication screen with session creationLayoutGrid, Heading, Text, loginLogin, Button
Registrationsignup.phpSelf-service registration & account creationLayoutGrid, Heading, Text, loginSignup, Button
Member Dashboardmembers.phpProtected portal for authenticated membersloginProtectPage, LayoutGrid, loginLoginName, loginLogout, Button
Profile & Securityprofile.phpSelf-service account profile and password updatesloginProtectPage, LayoutGrid, loginEditProfile, loginChangePassword, loginLogout
Admin Consoleadmin.phpAdministrator user directory managementloginProtectPage, LayoutGrid, loginAdmin, loginLogout
Password Recoveryrecover.phpLost credentials recovery flowLayoutGrid, Heading, Text, loginPasswordRecovery, Button

Native Tools & Configurations

All pages and authentication tools share the flat-file user database (./usersdb.php, database.type: 0), requiring zero MySQL/SQL server configuration:

  1. loginLogin (login.php):
  2. Layout: Responsive (login.style.layout: 1).
  3. Destination: Redirects authenticated users to members.php.
  4. Error Handling: Redirects invalid attempts to login.php.
  5. Features: Remember-me persistent cookie and password hashing.
  6. loginSignup (signup.php):
  7. Layout: Responsive (signup.style.layout: 1).
  8. Activation: Automatic activation (signup.approvalMode: 0), allowing users to log in immediately after registration.
  9. Destination: Redirects upon creation to login.php.
  10. loginProtectPage (members.php, profile.php, admin.php):
  11. Injects server-side PHP session verification at the top of the file before page rendering.
  12. Redirects unauthenticated visitors to login.php while preserving the intended target URL.
  13. loginLoginName (members.php, profile.php):
  14. Displays real-time logged-in user identity: "Logged in as: <username>".
  15. loginLogout (members.php, profile.php, admin.php):
  16. Native session destruction form button styled in slate red, redirecting back to index.php.
  17. loginEditProfile (profile.php):
  18. Self-service form allowing logged-in members to update their registered full name and email address.
  19. loginChangePassword (profile.php):
  20. Form verifying existing password and updating to a new hashed password.
  21. loginAdmin (admin.php):
  22. Embedded administrator management console with items pagination and user activation/editing tools.
  23. Administrator Password: admin123.
  24. loginPasswordRecovery (recover.php):
  25. Email-based password reset workflow.

Pre-Seeded Test Credentials

A starter database file (./usersdb.php) has been seeded in your project directory for testing:

  • Admin User:
  • Username: admin
  • Password: admin
  • Admin Console Password: admin123
  • Standard Member:
  • Username: demouser
  • Password: 123456
  • New Registration:
  • Navigate to signup.php to register any new username; accounts activate instantly and append directly to ./usersdb.php.