// Per-device "this is a shared computer" flag. localStorage is the source of // truth (shared-ness is a property of THIS browser, not the family — a DB // flag would force PIN mode on every device including a parent's phone). // A plain cookie mirror lets server loads see it too (localStorage never // reaches the server). Neither is a security boundary: the PIN + device // session cookies remain the actual gate (see shared-device.md). const LS_KEY = 'fam_shared_device'; const COOKIE = 'fam_shared_device'; export function isSharedDevice(): boolean { if (typeof localStorage === 'undefined') return false; try { return localStorage.getItem(LS_KEY) === '1'; } catch { return false; } } export function setSharedDevice(on: boolean) { try { if (on) localStorage.setItem(LS_KEY, '1'); else localStorage.removeItem(LS_KEY); } catch { /* private mode etc. — flag simply doesn't persist */ } if (typeof document !== 'undefined') { document.cookie = on ? `${COOKIE}=1; path=/; max-age=31536000; SameSite=Lax` : `${COOKIE}=; path=/; max-age=0; SameSite=Lax`; } }