A form can check what the user typed at two moments: before it is sent to the server and after it arrives there. Pega supports both, and a well-built application uses both for different reasons.
Client-side validation
These checks run in the browser before the form is submitted. The user gets feedback straight away and no server call is made.
- Required fields on the property or the field.
- Format and type checks, such as only digits in a number field.
- Simple field-level checks that show an error next to the field as soon as the user leaves it.
Server-side validation
These checks run after the form is submitted, on the Pega server. They can look at data the browser does not have.
- A Validate rule referenced from the flow action, which runs when the user submits.
- An Edit Validate rule (a Java routine) attached to a property.
- Custom checks in an activity or data transform that add messages to the page.
Comparison
| Client side | Server side | |
|---|---|---|
| Runs | In the browser, before submit | On the server, after submit |
| Speed of feedback | Immediate | After a round trip |
| Can check against the database | No | Yes |
| Can be bypassed | Yes, by a tampered request | No |
| Use for | Convenience and quick errors | Business rules and security |
A worked example
A bank opens an account. The form has an Email, a Date of Birth and a National ID.
- On the client, Email and Date of Birth are required, and Email must look like an email. The user sees the error at once.
- On submit, the server-side Validate rule checks that the applicant is at least 18, and that the National ID is not already in the customer table.
- If the ID exists, the rule adds a message to the National ID field, and Pega redisplays the form with the error.
Rule of thumb
Never depend on client-side checks alone. Anyone can send a request that skips the browser. Use client-side validation to be friendly, and server-side validation to be correct.
Interview tip
Say client-side checks run before submit for fast feedback, and server-side ones run after and enforce the business rules. Mention that you validate on both. Read on: Edit Validate and Edit Input and the Validate label.
Provide with relevant examples
ReplyDelete