Downloading Image with Secure Page Item

When images are user-specific or sensitive, use a hidden page item instead of X01.

For example, page 9005 is a copy of the image-serving page 9000, but it uses the hidden P9005_ID page item value for the P_ID parameter in its DOWNLOAD_BREAKROOM_IMAGE call.

Passing Checksum-Protected Hidden Page Item for Image ID

Description of the illustration protected-item-image-id.png

By default, pages use Arguments Must Have Checksum as the Page Access Protection setting as shown below. This causes APEX_PAGE.GET_URL to generate an additional checksum parameter in every URL. This extra token protects parameter values from manual manipulation.

Default Page Access Protection Setting Requires Checksum for URL Arguments

Description of the illustration args-must-have-checksum.png