Controlling Output Escaping in Substitution Strings

Learn about controlling output escaping in substitution strings.

You can escape special characters in the substitution value by appending an exclamation mark (!) followed by a predefined filter name to a page or application item name, report column, or other substitution string. Output escaping is an important security technique to avoid Cross Site Scripting (XSS) attacks in the browser. Oracle APEX already makes a best effort to automatically escape characters in a HTML or JavaScript context. With this extended syntax, developers have fine-grained control over the output.

Available Escape Filters

Available escape filters include: