namespace EntitlementBLL.Options;
///
/// Account-lockout threshold configuration for Entitlement client users, bound from appsettings
/// "Entitlement:ClientAccountLockout".
///
/// This is the real fix for the gap DXP shipped with: DXP's MDXPUSER.FAILEDLOGINCOUNT increments
/// on every wrong password and a Status==2 check exists in code, but nothing anywhere ever sets
/// Status to 2 — no threshold is ever read or enforced, so the lockout mechanism is entirely dead.
/// ClientAuthBLL.LoginAsync actually reads FailedLoginThreshold and flips
/// MENTITLEMENTCLIENTUSER.STATUS to Locked (2) once it's reached.
///
public class ClientAccountLockoutOptions
{
public const string SectionName = "Entitlement:ClientAccountLockout";
/// Consecutive failed login attempts against an Active account before STATUS is set
/// to Locked (2). Reset to 0 on any successful login or admin-initiated reactivation
/// (see ClientAuthBLL.SetClientUserStatusAsync).
public int FailedLoginThreshold { get; set; } = 5;
}