Was discussing authentication topics with my interns and found out that OWASP has resources about authentication (in cheetsheet series):
https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html
Nice checklist to have. Also if are not using their "standards" - at least recheck them sometimes.