namespace EntitlementBLL.Options; /// /// Account-lockout threshold configuration for Entitlement client users, bound from appsettings /// "Entitlement:ClientAccountLockout". /// /// This is the real fix for the gap DXP shipped with: DXP's MDXPUSER.FAILEDLOGINCOUNT increments /// on every wrong password and a Status==2 check exists in code, but nothing anywhere ever sets /// Status to 2 — no threshold is ever read or enforced, so the lockout mechanism is entirely dead. /// ClientAuthBLL.LoginAsync actually reads FailedLoginThreshold and flips /// MENTITLEMENTCLIENTUSER.STATUS to Locked (2) once it's reached. /// public class ClientAccountLockoutOptions { public const string SectionName = "Entitlement:ClientAccountLockout"; /// Consecutive failed login attempts against an Active account before STATUS is set /// to Locked (2). Reset to 0 on any successful login or admin-initiated reactivation /// (see ClientAuthBLL.SetClientUserStatusAsync). public int FailedLoginThreshold { get; set; } = 5; }