accounts.txt
I'm building <one sentence> with <stack> on <host>, and it now needs user
accounts.

First, recommend how: this stack's built-in or standard auth library, or
a hosted auth service. Pick one for my situation and justify it in three
lines. Don't hand-roll password handling.

Then the smallest working version: sign up, log in, log out, password
reset, and a single check for "is this person logged in". Include the
session and cookie settings that matter on this host, especially over
HTTPS.

Whatever you choose, check every page that shows data belongs to the person asking. Logged in is not the same as allowed.