Understanding Access Control

Adding the Access Control feature to an application, creates multiple pages and the following components: an Access Control region, access roles, authorization schemes, a build option, and an Application Setting.

About Adding Access Control

Learn about adding Access Control.

Running the Access Control Wizard creates multiple pages and the following components:

Developers use the access control list to associate the privileges, view, edit, and administration, with application users. Within the final Access Control UI, each privileges correlates to an access role:

See Also:

Attaching an Authorization Scheme to an Application, Page, or Components Managing Roles and User Assignments

About Access Control Authorization Schemes

Learn about Access Control authorization schemes.

When you add the Access Control feature to an application, the PL/SQL Body Wizard creates the following authorization schemes:

See Also: Attaching an Authorization Scheme to an Application, Page, or Components

About Configuring Access Control

Configure Access Control by running the application and accessing the Access Control region on the Administration page.

Once you add the Access Control feature, you configure it by running the application and accessing the Access Control region on the Administration page.

Description of the illustration admin_access_control.png

The Access Control region lists currently defined access roles and contains two sections: Users and Access Control.

Users

Click Users to add new users, change a user’s role, or disable access control by locking an account.

Tip: You add additional roles and configure role assignments on the Shared Components, Application Access Control page. See Managing Roles and User Assignments.

Access Control

Click Access Control to specify the behavior when authenticated users access the application.

For Any authenticated user may access this application, select one of the following:

See Also:

About Exporting an Application with Access Control

Learn about exporting an application with Access Control.

When your export an application with the Access Control feature, the application roles, Administrator, Contributor, and Reader, are exported. However, the users assigned to these roles are not exported. If you deploy a exported application with the Access Control feature, navigation menu entry for Administration page will not display. When you deploy an application with Access Control feature, your can add user roles as needed by going to Shared Components, Application Access Control. If the application is being deployed in a runtime environment, you can add user roles using APEX_ACL API. For example, the following example adds the user name ‘SCOTT’ as Administrator in application 255:

begin
    APEX_ACL.ADD_USER_ROLE (
        p_application_id => 255,
        p_user_name      => 'SCOTT',
        p_role_static_id => 'ADMINISTRATOR' );
end;

You can also execute the APEX_ACL API from the command line or create an install script in application supporting objects.

See Also: Attaching an Authorization Scheme to an Application, Page, or Components Managing Roles and User Assignments APEX_ACL in Oracle APEX API Reference