Ticket T117696
Visible to All Users
Duplicate

Suggestion: Put the allowed number of failed logon attempts to a field (remove hardcoding).

created 11 years ago (modified 11 years ago)

Please add the following field either to WebApplication and WinApplication classes or to their base XafApplication class:

C#
protected int maxLogonAttemptsCount = 3;

…and replace the hardcoded value (3) with this field in the following places:
WinApplication.Logon():

C#
if(logonAttemptCount < 3) { ..... }

WebApplication.Logon():

C#
if(logonAttemptCount >= 3) { ..... }

Answers approved by DevExpress Support

created 11 years ago

Hello Krzysztof,
Thank you for your valuable feedback. We already have this feature in our plans as simple security improvements, but currently I cannot provide you with any estimate.
Please let me know if you need further assistance.

    Show previous comments (3)
    Dennis Garavsky (DevExpress) 11 years ago

      Thanks for the reminder, guys. It will be available in the next version.

      KK KK
      Krzysztof Krzyzsłof 11 years ago

        Dennis. Great as always!

        Dennis Garavsky (DevExpress) 11 years ago

          Welcome!

          Disclaimer: The information provided on DevExpress.com and affiliated web properties (including the DevExpress Support Center) is provided "as is" without warranty of any kind. Developer Express Inc disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. Please refer to the DevExpress.com Website Terms of Use for more information in this regard.

          Confidential Information: Developer Express Inc does not wish to receive, will not act to procure, nor will it solicit, confidential or proprietary materials and information from you through the DevExpress Support Center or its web properties. Any and all materials or information divulged during chats, email communications, online discussions, Support Center tickets, or made available to Developer Express Inc in any manner will be deemed NOT to be confidential by Developer Express Inc. Please refer to the DevExpress.com Website Terms of Use for more information in this regard.