> I literally just spent about a month hacking on flask-security to get the login/email-confirmations/email templates/argon2-hashing/2-factor-auth the way I need it.
I don't know Anvil but I am sure it has a specific way of dealing with login/signup/... - just like every other framework. And if you want to modify it, well, that takes time. And I am guessing it was the same with other tasks.
There is nothing wrong with that, of course. Just saying. :)
Anvil's built in "Users" service is incredibly simple and un-magical (user records are just database rows, and you can reimplement vanilla password login in four lines). This makes hacking on it an awful lot easier than some magically injected extension that needs to be configured just so.
(Check out the API: https://anvil.works/doc#users)
One example is the way the request context works in flask, I venture to say thats just terrible software design in my book (from flask import request, g). And seriously to have your framework give you a "global" variable to put random stuff in, wth?
Also I rather not use Flask-SQLAlchemy since why should my database models be tied so incredibly closely to some library of my web MICRO framework, it doesn't make sense, I mean its not django why introduce this coupling?
It seems if you need all the dependent libraries (like webassets and wtforms) just use django from the get go instead of going through the pain of trying to cleanly integrate dozens of flask libraries.
To see how a proper simple middleware-based framework should look like consider express, koa (nodejs), or bottle, falcon. Aiohttp and tornado also have their place of course.
Flask/etc was useful magic only until I figured out what it really does between me and underlying socket.
With AWS Lambda, Python, AWS Cognito, Postgres and ReactJS I can build large scale complete applications.
I think I'm vastly more productive today than I was then. That's partly a function of being a much better programmer in general, partly about now having developed expertise with my chosen technology set.
There's no way I'd go back to something as bare bones as Bottle or Flask any more. If I had to use a Python framework I'd look at a batteries included system like Django. As I say however, I've settled on Lambda, Cognito, Python, Postgres and ReactJS. I've done the hard yards... years of learning and many thousands of lines of code written.
>> Need to subclass and override much of it to finally have something usable.
This is really not something you should be spending your minimal available programming time doing.
After having done it a few times I personally don't find Flask auth very time consuming to implement.
But I'll admit I really like Flask. I find it just the right approach between something simple and something that can be much more complex with extensions. I don't like all of the extension (WTF Forms for instance can do without and SQL Alchemy usually is better independent of Flask IMOP) but these don't need to be used. I've stuck with Flask as much as possible over the years and that alone has led to a huge productivity increase for me because of familiarity.