Urgent.News

What's breaking now, across thousands of outlets.

Tech

A customer maintenance form in Uniface 10, part 9 - users, roles, a change history and a login lockout

Up to part 8 the app had no idea who was using it. Every change was stamped with $user , the Windows login, and every user could do everything. For a single-user desktop tool that is fine. As soon as a second person works with the same customer file, three questions come up: Who changed this customer? What exactly was changed, and what was the value before? Who is allowed to change anything at…

Uniface 10 introduced a new customer maintenance form in part 9, addressing issues around users, roles, change history and login lockout. Previously, the application lacked any awareness of who was using it, treating every user equally with the same rights.

With the new USER_SVC service, users, passwords and roles are now managed. A change log, HISTORY_SVC, records field-level changes, while AUDIT_SVC keeps a login log with lockout and password rules.

Three tables were created to implement these services: APP_USER stores user details, CUSTOMER_HISTORY logs changes to customer records, and APP_LOGIN_LOG records login attempts. Indexes were also added for faster data retrieval.

The application now has three roles: READ, EDIT and ADMIN. Comparisons between roles are handled using a numeric comparison system, rather than multiple if statements. The HAS_RIGHT operation checks if a user has the required right based on their role.

Successful logins store the user name and role in global registers $91 and $92, available throughout the application's lifetime. These values are visible in every component, similar to the desktop session's lifetime.

Upon a successful login, the CURRENT_USER operation populates $91 and $92 with the logged-in user's name and role. If no login is detected, the application defaults to the Windows user with EDIT rights.

If the user table is empty, the first login creates an administrator user with all rights. The last administrator cannot be deactivated or demoted to another role. Passwords are stored as HMAC-SHA256 hashes, keyed with a fixed prefix and the upper-cased user name, ensuring different hashes for the same password among different users.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at dev.to →

More in Tech

7 checks I run on a number before it goes in front of money

The number that embarrasses you is never the obvious lie. It's the ordinary-looking one everybody nods past, because it's already in the deck and the deadline was yesterday.

  • Determine if the figure is a rate or a score
  • Identify the denominator for accurate comparison
  • Ascertain who selected the sample and excluded participants

More from Sunday 4 October →