{
  "id": 11855645,
  "title": "A customer maintenance form in Uniface 10, part 9 - users, roles, a change history and a login lockout",
  "url": "https://urgent.news/2026/10/04/a-customer-maintenance-form-in-uniface-10-part-9-users-roles-a-change",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-04T05:41:19.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/f345345dfg/a-customer-maintenance-form-in-uniface-10-part-9-users-roles-a-change-history-and-a-login-e91"
  },
  "original_language": "en",
  "account": "Uniface 10 introduced a new customer maintenance form in part 9, addressing issues around users, roles, change history and login lockout. Previously, the application lacked any awareness of who was using it, treating every user equally with the same rights.\n\nWith the new USER_SVC service, users, passwords and roles are now managed. A change log, HISTORY_SVC, records field-level changes, while AUDIT_SVC keeps a login log with lockout and password rules.\n\nThree tables were created to implement these services: APP_USER stores user details, CUSTOMER_HISTORY logs changes to customer records, and APP_LOGIN_LOG records login attempts. Indexes were also added for faster data retrieval.\n\nThe application now has three roles: READ, EDIT and ADMIN. Comparisons between roles are handled using a numeric comparison system, rather than multiple if statements. The HAS_RIGHT operation checks if a user has the required right based on their role.\n\nSuccessful logins store the user name and role in global registers $91 and $92, available throughout the application's lifetime. These values are visible in every component, similar to the desktop session's lifetime.\n\nUpon a successful login, the CURRENT_USER operation populates $91 and $92 with the logged-in user's name and role. If no login is detected, the application defaults to the Windows user with EDIT rights.\n\nIf the user table is empty, the first login creates an administrator user with all rights. The last administrator cannot be deactivated or demoted to another role. Passwords are stored as HMAC-SHA256 hashes, keyed with a fixed prefix and the upper-cased user name, ensuring different hashes for the same password among different users.",
  "summary": "Up to part 8 the app had no idea who was using it. Every change was stamped with $user , the Windows login, and every user could do everything. For a single-user desktop tool that is fine. As soon as a second person works with the same customer file, three questions come up: Who changed this customer? What exactly was changed, and what was the value before? Who is allowed to change anything at…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Dev.to",
        "title": "A customer maintenance form in Uniface 10, part 1 - from an empty IDE to working CRUD on SQLite",
        "url": "https://urgent.news/2026/10/04/a-customer-maintenance-form-in-uniface-10-part-1-from-an-empty-ide-to",
        "published": "2026-10-04T05:07:43.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}