On the other hand, looking at node.js it's really a dumpster fire[1]. Even when using passport, you are still back to writing the code to compare passwords at which point so much can go wrong. So there's a lot of scope for hosted services. This of course compounds the problem because those service providers are GREAT at SEO and content marketing, so now a lot of Google hits on nodejs auth end up recommending Auth0 &friends.
[1] https://medium.com/hackernoon/your-node-js-authentication-tu...
I'm not sure I agree. This isn't really an infrastructure cost, it's a direct COGS (cost of goods sold) cost, and hits the service's margin. For a SaaS business charging $10-1000 per month per user it's fine.
For a retail business though I think this could be prohibitively expensive. Let's say you have a 10% conversion rate and $100 a year spend for customers, that's actually only $0.83 a month per active user. This is a 6% margin hit.
Sure, maybe in retail you often don't need non-customers to log in, but maybe you do. Or maybe your active users correlate much more strongly with your paying users, but maybe they don't. Content-led, email newsletter style business could struggle with this pricing.
Allauth itself is opinionated, and some things were built based on expectations that are not reflective of today’s web apps.
It can be done but the lift is much bigger than one might think.
I also think one of the most important parts of django is user/auth.
Seeing FastAPI and modern frontends continually advance, and now this user management service, I’d suggest that Django is getting unbundled.
The missing part to me seems to be a stand alone ORM and something to replace traditional view/templates so existing django devs could onboard easier. Maybe these already exist or are in development?
I really like Django, but I do feel like there has been too much emphasis on stability and not enough experimentation to integrate API and modern frontend work into core.
I think some of this has to do with how unstable django was in its earlier days. Sort of a ptsd from that.
However, what has been forgotten is that it also allowed the project to handle changing developer needs and take market share from Drupal and others.
The best example I have seen of this problem is in the ecommerce package, Solear.
If you listen to the project founders in the the 4/2019 Python podcast, “Building Scalable Ecommerxe Sites on Saleor” you can hear the use case of the project falling away as modern frontend is coming into focus. [1]
The challenge is that was two years ago.
I actually see this as a problem for Python even beyond Django.
[1] https://www.pythonpodcast.com/saleor-ecommerce-episode-205/
I would love to see allauth extended with some sort of React toolkit so we could do SPA logins without refresh. That seems like a much smaller lift..