5 ms·
I went down the rabbithole of using next-auth (now authjs) for a recent project. Having used Passport.js [1] for Oauth2 the last time I was doing node.js ~3 yea
by sirius87 4y ago
I went down the rabbithole of using next-auth (now authjs) for a recent project. Having used Passport.js [1] for Oauth2 the last time I was doing node.js ~3 years ago, I found this library to have many footguns as comments/answers on SO and Github.
Seems like many people are trying to shoehorn their codebase [2] (!!) to make it work with the way the library manages sign-in flow, redirects, cookies, logout, etc. [3]
These were solved problems in the MEAN stack era with middlewares, but now that Next.js/react is the trend, people are doing everything they can to make it work - from relaxing security configs, to stashing things in the JWT just so some callback can get an additional piece of data [4].
[1] https://github.com/jaredhanson/passport https://github.com/jaredhanson/passport
[2] https://github.com/nextauthjs/next-auth/issues/600#issuecomment-1235488781 https://github.com/nextauthjs/next-auth/issues/600#issuecomm...
[3] https://stackoverflow.com/questions/tagged/next-auth?sort=MostVotes https://stackoverflow.com/questions/tagged/next-auth?sort=Mo...
[4] https://stackoverflow.com/questions/64576733/where-and-how-to-change-session-user-object-after-signing-in https://stackoverflow.com/questions/64576733/where-and-how-t...
EDIT: more links in case it helps the authors improve DX
- thinkingkong 4y agoAgreed. This library is so opinionated that it more or less becomes useless. Youre way better off using iron-session or just go all the way and use a provider like Auth0, etc.
- 0xblinq 4y agoAgree. iron-session is great
- moojd 4y agoThe nextjs team for the longest time seemed openly hostile to server-side features in the GitHub issues. We ended up using the custom server feature to essentially bypass nextjs entirely so we could adequately do things like server-side auth in an explicit way using existing proven middleware. Next auth was inadequate for us mostly because of the limitations of nextjs itself. Nextjs 13.1 just added actual server-side middleware with full control of requests/responses so hopefully things will improve. I haven't fully investigated it yet but I'm hoping we can rip out all of our custom server stuff and replace it with middleware now.
- sirius87 4y agoSame. I found this example [1] particularly helpful, although I don't know how good this [2] library it uses is. Overall, I've seen multiple OSS projects [3] that try to support a missing functionality in Next.js seem to just give up trying to keep up with their breaking changes. [1] https://stackblitz.com/edit/github-mwzv1t?file=README.md https://stackblitz.com/edit/github-mwzv1t?file=README.md [2] https://github.com/hoangvvo/next-connect https://github.com/hoangvvo/next-connect [3] https://github.com/cyrilwanner/next-optimized-images https://github.com/cyrilwanner/next-optimized-images
- Kiro 4y agoIf you need to bypass Next.js, why use it at all?
- moojd 4y agoWe are using nextjs for everything it can do, while bypassing it for the things it can't. With 13.1 that shouldn't be necessary because it is now more capable.
- deckard1 4y ago> Nextjs 13.1 just added actual server-side middleware the middleware has been available for awhile, they just added a few "advanced" features it looks like. The problem with their middleware is that it's based on their edge runtime. Which is pretty much very basic web APIs and nothing more. Unlike Express/Koa, you do not have the full node API and cannot do things like read files from the filesystem. It's a total unnecessary clusterfuck just so Vercel can get you on their cloud services. Every single day I work with Next.js I wish I had Express and a decent router.
- super256 4y agoI like fastify more than express due to the great opinions (json schema, hooks etc). I use fastify + the fastify-nextjs plugin. It works great and lets you expose custom request decorations from node.js to next.js. Maybe this can help you too: https://github.com/fastify/fastify-nextjs https://github.com/fastify/fastify-nextjs The only drawback is the slow startup time of next.js, which becomes really annoying with huge next.js projects. But for smaller projects, fastify-nextjs is fine.
- cco 4y agoI work at Stytch, a company that provides an authentication API > Seems like many people are trying to shoehorn their codebase... This is something we're always thinking about in our product; write API first and flexibly enough so developers don't have to do cartwheels to use our product. If you ever need to jump into authentication in Node again, give us a look!
- FBISurveillance 4y agoYou folks gave a great product. Do you have plans to support next-auth? If not, would you mind telling why? I've been struggling to integrate Stytch SDK with next-auth even though there's a tutorial for magick.link [0] that I tried to replicate to no avail. [0] https://dev.to/narciero/using-nextauth-js-with-magic-links-df4 https://dev.to/narciero/using-nextauth-js-with-magic-links-d...
- SlickStef11 4y ago> Seems like many people are trying to shoehorn their codebase... Full Disclosure: I work at WunderGraph But I think you should take a look at WunderGraph. It's vendor agnostic and allows you to choose a authentication provider that will work with your codebase. You can use Keycloak, Auth0, Ory, etc... https://docs.wundergraph.com/docs/features/openid-connect-based-authentication https://docs.wundergraph.com/docs/features/openid-connect-ba...