There's so many tiny details and edge cases that can have such catastrophic results, it's too much of a risk to do it yourself. Unless writing auth frameworks is your job, for course.
There's so many tiny details and edge cases that can have such catastrophic results, it's too much of a risk to do it yourself. Unless writing auth frameworks is your job, for course.
I think that the Node ecosystem tends toward minimalism and compartmentalization in modules, and in doing so monolithic authentication solutions don't really exist like they do in other frameworks in which there's more "magic", like Ruby/Rails.
You'd have to choose a higher-level Node.js-based framework, and there isn't an emergent solution yet. Personally I've been directed toward Hapi and Feathers.js as of late. Feathers I committed some PRs to and filed some issues against this weekend, which the maintainers are taking seriously, but it could use some more functionality and deeper testing. Hapi I haven't personally looked at, but is backed by some of the Auth0 guys.
Writing a secure auth isn't exactly hard, and there is good info on the web about it. It just requires time to implement and not taking shortcuts to do it right.
In node there are not really official solutions - it's just packages. Php has a nice password_hash function which hashes and salts your password for you securely.
Most of us have made our careers standing upon the shoulders of relative giants until we have grown enough to become taller ourselves. I don't believe that you should have to be able to build a reliable authentication framework to be able to write a decently secure web application.