most basic:
login screen -> user check, if successful set user + password in session variables. in every further page user check again on the top.
on fail return to login screen.
lookup: session_start, session_destroy, session_register, header
in a peanutshell!