I can't believe this is the current state of web app development. I know everyone's moved on to Node and Angular, but, c'mon!
I can't believe this is the current state of web app development. I know everyone's moved on to Node and Angular, but, c'mon!
1. https://docs.djangoproject.com/en/1.9/topics/auth/customizin...
And I don't see how assertions like this can be made: "This will usually be a username of some kind, but it can also be an email address"
Except for HN, Twitter & Reddit, are there any services that don't use email for login?
I guess sites that use the username as a form of identity within a site. Email address usernames are just identifiers and contact information, without really being linked to an identity.
I would think if auth was being written from scratch it'd probably default to email based usernames. That ship has sailed though.
Which meant that Django's database models couldn't migrate.
Even now, there is no real way to start with Django's own User model and switch your project over to a custom one later (because you'd have many database tables with foreign keys to the Django one). The current recommendation is to start new projects with a custom User model always.
However, you can use Django AllAuth (https://github.com/pennersr/django-allauth) to achieve an email login system by tweaking its settings.
Specifically:
ACCOUNT_AUTHENTICATION_METHOD = "email"
ACCOUNT_USERNAME_REQUIRED = False (if you do not want to use the username field)
More here: http://django-allauth.readthedocs.org/en/latest/configuratio...
Cheers!
In Django's case I would say their Authentication model was an opinionated choice that has since become a major staple of Django. Many frameworks will not include default ORM-models and will instead defer to the user to implement their own authentication scheme.
Personally I disagree with this choice, I think database schemas have to be flexible and an in-framework authentication setup will only encourage users to lean more on the framework even when it is working against them. I've burned plenty of hours in Django trying to work / extend the authentication model. While I have no doubt much of this was due to my inexperience with Django, there is a certain responsibility with having a framework used by many beginners who will struggle and perhaps pick up bad habits (like expecting your web framework to automagically solve everything) if you do not design it for them.
Overall I think Django is awesome. But it's not for every use-case, or every developer. About a year ago I moved over to NodeJS professionaly, some day I will perhaps go back but have yet to have any significant reason to do so.
Django really is quick and easy to get going though. If you can make your way past the email based usernames, I think you'd find a really capable and easy system waiting for you.
[0] - https://github.com/pydanny/cookiecutter-django
[1] - https://github.com/pennersr/django-allauth
[2] - http://django-allauth.readthedocs.org/en/latest/configuratio...
I agree this should probably have a solution or at least documentation to be wary of.
My big issue with the current state though is that if you're relying on usernames or email addresses being unique then you're potentially opening yourself up to all sorts of security issues without realizing it.
I'd probably prefer a functional unique index since it would be easier to maintain (rather than duplicate fields). We just need to get expression support into indexes.