I've now been writing django at work for five years and still have yet to come across a query builder/orm which is as powerful yet simple in addition to being a breeze to on-board new engineers with.
When there are queries that require the use of non-django builtins, it's also relatively easy to use django raw sql or just straight up use the psycopg2 sql.SQL dynamic string composition helpers.
With the complexity of some our chained django QueryMethods, the company would have quite literally been impossible to build without django's query builder, at the very least.
At scale, poorly understood ORM-generated queries can be a real pain, especially if your team's SQL skills have atrophied due to over-reliance on the ORM.
As an exercise, I'd possibly recommend reviewing your top 1-3 worst performing queries, tracking them back to the ORM, and evaluating how to improve them.
People often overestimate how often the average website needs to worry about scale.
And how easy it is to fix the times you come close.
Edited to say: as for the average website, I do completely agree. For the unique website that will scale as well, I likely would still 95/100 recommend the ORM, but my experience has taught me that there be some pain on the road.
Yes, of course.
Yes, people are still using Django.
As I've grown in my career, frameworks, libraries, and architectural patterns just become tools. I don't quite understand folks who identify as a "React developer", or a "Django developer". When evaluating any framework, you must learn to eschew the latest hotness long enough to evaluate what your requirements are, and maybe most importantly, what your constraints are.
For a surprising amount of projects today, I would still recommend Django above anything else.
import os
from django.conf import settings
from django.core import management
from django.conf.urls import url
from django.http import HttpResponse
# Django 2.2 Release Notes
# https://docs.djangoproject.com/en/4.1/releases/2.2/
# Documentation
# https://docs.djangoproject.com/en/2.2/
__version__ = 0.1
DEBUG = True
ROOT_URLCONF = 'project'
DATABASES = {'default': { 'ENGINE': 'django.db.backends.sqlite3', 'NAME': 'project.db' }}
SECRET_KEY = os.getenv('SECRET_KEY', 'Please set a SECRET_KEY as an env var.')
if not settings.configured:
settings.configure(**locals())
def index(request):
return HttpResponse('Hello Django!')
urlpatterns = [
url(r'^$', index),
]
if __name__ == '__main__': # pragma: no cover
management.execute_from_command_line()With that being said, I hadn't thought much about "before Flask". I very well might feel differently if I had been coding then.
- Admin panel? Django has me
- Web forms? Django has me
- Testing? Django, again has an out of the box solution
- Latest in security practices[0]? Again, covered for free
Flask, boy oh boy. I want an ORM? Guess I have to search around, Flask-SQLAlchemy has a lot of hits, I guess? Emails? Well, the Flask Mega-Tutorial uses Flask-Mail[1], guess I will use that. Oh look, it has not been updated since 2014[2]. Hope there is not a security flaw in there[3].
Django follows best practices, and has a huge community ensuring that there is adequate coverage and features required for modern development.
[0]: https://docs.djangoproject.com/en/4.2/releases/4.2/ note on the BREACH attack
[1]: https://blog.miguelgrinberg.com/post/the-flask-mega-tutorial...
I am by no means a fan of flask. However it gives you a lot more freedom to structure your application to your taste. Django is basically a php 5.4 framework with a python syntax.
In this day and age fastAPI is a solid choice, so is falcon and probably half a dozen others.