Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A Uniface 10 customer form becomes a business application when it does more than save records: it enforces business rules, models related data, protects access on the server, and records important activity for operations. These four concerns are a practical way to organize the design—not a formally named Uniface checklist.

1. Put business rules behind the fields

A field is not just a box on the screen. Uniface documents storage, field syntax, and display properties separately. At runtime, it checks entered or changed data against the field’s data type and any defined field syntax. Rocket Software’s Fields guide for Uniface 10 also describes ValRep lists and ranges, and field triggers for event processing.

Use those mechanisms for rules that belong to an individual field: its data type, acceptable syntax, and permitted values. For rules that involve several fields or a business process, determine where the rule should be enforced and make sure it runs when the data is actually received or changed. The available guidance does not prescribe a customer-specific rule set, so requirements such as which customer details are mandatory must come from the application’s own business needs.

Keep the distinction between validation and presentation clear. A display property affects how a value is shown; it does not, by itself, establish that the stored value meets a business rule.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Model customer relationships explicitly

A customer record rarely stands alone. Uniface relationships represent associations between entities, with keys and delete constraints defining important aspects of how those associations are maintained. The Uniface Concepts guide for V9.7 describes one-to-many relationships and explains that many-to-many relationships require an intermediate entity.

One customer with multiple related records

For a one-to-many association, identify the key that connects the records and decide what should happen to associated data when a record is deleted. A delete constraint is part of that model; deletion behavior should be intentional rather than left as an accidental side effect of a form action.

Rank #2

Many-to-many associations

When records on both sides can be associated with multiple records on the other side, model the association through an intermediate entity. This makes the relationship explicit and gives the application a place to represent the association itself.

The relationship details cited here come from the V9.7 Concepts material, not a 10.4 release note. Treat them as core modeling guidance and verify implementation details against the Uniface release and patch you deploy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Enforce access and validation beyond the browser

A web form can give users immediate feedback, but browser-side checks are not a security boundary. Rocket Software’s Rocket Uniface Web Security Guidelines V10.4 says the application should not rely on validation done by the browser and calls for validating received input. Apply the rule where the application handles that input, not only in a client-controlled interface.

Authorization also needs to cover more than whether a user can open a customer screen. The V10.4 guidance addresses confidential-data access, data manipulation, unauthorized commands, and privilege escalation. Decide which roles may view sensitive customer information and which may perform actions such as changing or deleting records. Check permissions early, and use centralized authorization so that access decisions are not scattered inconsistently across the application.

Client-side validation can still improve usability by showing errors sooner. It complements, but does not replace, server-side validation and authorization.

4. Make activity observable for operations

Logging gives operators evidence to investigate activity; it is not an automatic audit trail supplied merely by having a maintenance form. The V10.4 security guidance recommends enabling application and server logging and recording significant actions, including logon attempts and database access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose which events matter for the application, configure the relevant application and server logs, and ensure the resulting records can support operational investigation. Do not describe this as a complete audit capability unless the application has actually been designed and configured to provide one.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check the release documentation before implementation

Rocket Software’s documentation catalog lists Uniface Library 10.4, updated in September 2026. The field guidance is under Uniface 10 documentation without a clear publication date, the security guidance is V10.4 © 2024, and the relationship source is explicitly V9.7. Because those sources span versions, check syntax and release-specific behavior in the documentation for the exact Uniface patch you deploy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.