// Display-only masking for OTP screens — never changes the actual
// value used for API calls, only what's shown on screen.

export function maskMobileNumber(mobile: string): string {
  const digits = mobile.replace(/\D/g, "");

  if (digits.length <= 2) return digits;

  const lastTwo = digits.slice(-2);
  return "*".repeat(digits.length - 2) + lastTwo;
}

export function maskEmail(email: string): string {
  const [local, domain] = email.split("@");

  if (!local || !domain) return email;

  const maskPart = (part: string) =>
    part.length <= 2 ? part : part.slice(0, 2) + "*".repeat(Math.max(part.length - 2, 3));

  return `${maskPart(local)}@${maskPart(domain)}`;
}
