Add login without rolling your own
The one area where "just use the boring library" is not negotiable.
I need users to log in. My stack: <stack>. Expected users: <a handful / hundreds / thousands>. First: recommend whether I should use a hosted auth provider or a well-established library in my framework. Pick one and justify it in three lines. Do not suggest I implement password hashing and session handling myself. Then give me the smallest working integration: sign up, log in, log out, and "is this request authenticated?". Nothing else yet.
Password resets, session fixation, timing attacks, token rotation. Every one is a solved problem and every one is a way to leak your users' data if you improvise it.