This does not require MySQL, true, but if you're going to use MySQL don't forget to escape your variables.
$user = $mysqli->real_escape_string($_POST['user']);
$pass = $mysqli->real_escape_string($_POST['pass']);

Where $mysqli is your MySQLi connection.