# Session handling in Ember

**URL:** <https://discuss.emberjs.com/t/session-handling-in-ember/13474>\
**Category:** Search\
**Created:** [August 16, 2017, 9:29am UTC](https://discuss.emberjs.com/t/session-handling-in-ember/13474 "2017-08-16T09:29:26Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![parekhpiya2002](https://avatars.discourse-cdn.com/v4/letter/p/74df32/32.png) [@parekhpiya2002](https://discuss.emberjs.com/u/parekhpiya2002)\
**Post date:** [August 16, 2017, 9:29am UTC](https://discuss.emberjs.com/t/session-handling-in-ember/13474/1 "2017-08-16T09:29:26Z")

</div>

Hello All,

How to handle session after login in Ember

Thanks in Advance, Priyanka

---

<div class="post-metadata">

**Author:** ![heatbr](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/heatbr/32/9874_2.png) [@heatbr](https://discuss.emberjs.com/u/heatbr)\
**Post date:** [August 16, 2017, 1:33pm UTC](https://discuss.emberjs.com/t/session-handling-in-ember/13474/2 "2017-08-16T13:33:54Z")

</div>

Use some addons that handle it. Torii and Simple Auth are best choice. [GitHub - simplabs/ember-simple-auth: A library for implementing authentication/authorization in Ember.js applications.](https://github.com/simplabs/ember-simple-auth) [Torii](http://vestorly.github.io/torii/)

---

<div class="post-metadata">

**Author:** ![broerse](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/broerse/32/9497_2.png) [@broerse](https://discuss.emberjs.com/u/broerse)\
**Post date:** [August 16, 2017, 2:32pm UTC](https://discuss.emberjs.com/t/session-handling-in-ember/13474/3 "2017-08-16T14:32:09Z")

</div>

> <https://github.com/broerse/ember-cli-blog/blob/master/app/controllers/login.js>

---

<div class="post-metadata">

**Author:** ![Chendraayan](https://avatars.discourse-cdn.com/v4/letter/c/90ced4/32.png) [@Chendraayan](https://discuss.emberjs.com/u/Chendraayan)\
**Post date:** [May 23, 2018, 12:17pm UTC](https://discuss.emberjs.com/t/session-handling-in-ember/13474/4 "2018-05-23T12:17:16Z")

</div>

However, the authenticated states are maintained in service, which you can easily change using ember inspector. And they are deprecating authorization also. How secure is to maintain the states in ember service?

---

<div class="post-metadata">

**Author:** ![heatbr](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/heatbr/32/9874_2.png) [@heatbr](https://discuss.emberjs.com/u/heatbr)\
**Post date:** [June 4, 2018, 1:57pm UTC](https://discuss.emberjs.com/t/session-handling-in-ember/13474/5 "2018-06-04T13:57:56Z")

</div>

the authenticated states hold only a token, your backend must be ready to validate it and decode that token. Even a basic user password auth must be validate in your backend.

Sorry about the delay, hope you already got your solution.

---

<div class="post-metadata">

**Author:** ![Chendraayan](https://avatars.discourse-cdn.com/v4/letter/c/90ced4/32.png) [@Chendraayan](https://discuss.emberjs.com/u/Chendraayan)\
**Post date:** [June 21, 2018, 12:21pm UTC](https://discuss.emberjs.com/t/session-handling-in-ember/13474/6 "2018-06-21T12:21:09Z")

</div>

Thanks for the reply. My backend team is handling it.

---

<div class="post-metadata">

**Author:** ![localpcguy](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/localpcguy/32/13643_2.png) [@localpcguy](https://discuss.emberjs.com/u/localpcguy)\
**Post date:** [June 21, 2018, 2:55pm UTC](https://discuss.emberjs.com/t/session-handling-in-ember/13474/7 "2018-06-21T14:55:11Z")

</div>

Something to remember - nothing client-side can be consider “secure”, so everything needs to be validated by the API any time something requiring validation is done. You can do a few things, like not storing sensitive things like the user’s password in plain text in a cookie or localStorage. But the token needs to be stored somewhere if you want to be able to try to re-establish the session on page refresh (where the service would be reset). The server should reset the token on a timely basis (every X number of minutes) so that if it is compromised the damage can be mitigated. Also, re-require password for sensitive changes (like changing the password, email address) and re-validate that password against the API prior to making those kinds of changes.

---

<div class="post-metadata">

**Author:** ![Chendraayan](https://avatars.discourse-cdn.com/v4/letter/c/90ced4/32.png) [@Chendraayan](https://discuss.emberjs.com/u/Chendraayan)\
**Post date:** [June 26, 2018, 10:53am UTC](https://discuss.emberjs.com/t/session-handling-in-ember/13474/8 "2018-06-26T10:53:27Z")

</div>

> [@localpcguy](#):
>
> But the token needs to be stored somewhere if you want to be able to try to re-establish the session on page refresh (where the service would be reset).

Thanks for the suggestions. It makes sense.

---

<div class="post-metadata">

**Author:** ![rtablada](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/rtablada/32/13679_2.png) [@rtablada](https://discuss.emberjs.com/u/rtablada)\
**Post date:** [June 27, 2018, 5:56pm UTC](https://discuss.emberjs.com/t/session-handling-in-ember/13474/9 "2018-06-27T17:56:24Z")

</div>

> [@Chendraayan](#):
>
> However, the authenticated states are maintained in service, which you can easily change using ember inspector.

In production you can disable the Ember inspector using `window.NO_EMBER_DEBUG = true` which will disable the inspector from loading.

That said, if a user knows to use Ember Inspector they probably know their way around most of the dev tools in modern browsers so will have access to cookies, network logs, and more. There’s not too much you can do to stop that. Cookies and auth session tokens are fairly easy to grab and share if you know what you’re doing. Your best defense is a short lived session with a refresh token and possibly IP or device verification server side.
