feat: complete release readiness work
- consolidate API ownership and remove dead vendor code - add Stripe billing, learning paths, and public CV hardening - add migration, recovery, security, audit, and browser gates
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
namespace JobTrackerApi.Models;
|
||||
|
||||
// "Trust this device for 30 days" -- lets a browser skip the 2FA code step after one successful
|
||||
// challenge. Never store the plaintext token, only its SHA-256 hash, same rationale as
|
||||
// TwoFactorRecoveryCode.CodeHash: a DB read (backup, replica, leaked snapshot) can't be turned
|
||||
// into a working cookie.
|
||||
public sealed class TrustedDevice
|
||||
{
|
||||
public int Id { get; set; }
|
||||
public string UserId { get; set; } = "";
|
||||
public string TokenHash { get; set; } = "";
|
||||
public string? DeviceLabel { get; set; }
|
||||
public DateTimeOffset CreatedAtUtc { get; set; }
|
||||
public DateTimeOffset LastSeenAtUtc { get; set; }
|
||||
public DateTimeOffset ExpiresAtUtc { get; set; }
|
||||
}
|
||||
Reference in New Issue
Block a user