I think Django has by far the best story here, so much built in or activated with simple plugins. It took us an hour to add 2FA.
On the other hand, looking at node.js it's really a dumpster fire[1]. Even when using passport, you are still back to writing the code to compare passwords at which point so much can go wrong. So there's a lot of scope for hosted services. This of course compounds the problem because those service providers are GREAT at SEO and content marketing, so now a lot of Google hits on nodejs auth end up recommending Auth0 &friends.
[1] https://medium.com/hackernoon/your-node-js-authentication-tu...