namespace JobTrackerApi.Models; // "Trust this device for 30 days" -- lets a browser skip the 2FA code step after one successful // challenge. Never store the plaintext token, only its SHA-256 hash, same rationale as // TwoFactorRecoveryCode.CodeHash: a DB read (backup, replica, leaked snapshot) can't be turned // into a working cookie. public sealed class TrustedDevice { public int Id { get; set; } public string UserId { get; set; } = ""; public string TokenHash { get; set; } = ""; public string? DeviceLabel { get; set; } public DateTimeOffset CreatedAtUtc { get; set; } public DateTimeOffset LastSeenAtUtc { get; set; } public DateTimeOffset ExpiresAtUtc { get; set; } }