Understanding Authentication

Learn about authentication.

How Authentication Works

Lean how authentication works.

You determine how your application interacts with users. If all users have the same rights and privileges, they are referred to as public users. However, if your application must track each user individually, you must specify an authentication method.

Authentication establishes the identity of each user who accesses your application. Many authentication processes require that a user provide some type of credentials such as a user name and password. These credentials are then evaluated and they either pass or fail. If the credentials pass, the user has access to the application. Otherwise, access is denied.

Once a user has been identified, the Oracle APEX engine keeps track of each user by setting the value of the built-in substitution string APP_USER. As a user navigates from page to page, the APEX engine sets the value of APP_USER to identify the user. The APEX engine uses APP_USER as one component of a key for tracking each user’s session state.

From a programming perspective, you can access APP_USER using the following syntax:

You can use APP_USER to perform your own security checks and conditional processing. For example, suppose you created the following table:

CREATE TABLE my_security_table (
  user_id   VARCHAR2(30),
  privilege VARCHAR2(30));

Once created, you could populate this table with user privilege information and then use it to control the display of pages, tabs, navigation bars, buttons, regions, or any other control or component.

See Also:

About Support for Deep Linking

Learn about support for deep linking.

APEX applications that use authentication schemes support deep linking. Deep linking refers to the ability to link to an APEX page out of context (for example, from a hyperlink in an email or workflow notification). When you link to a page out of context and the application requires the user be authenticated, the user is taken to the Sign In page. After credentials verification, the APEX engine automatically displays the page that was referenced in the original link. Deep linking is disabled by default. Application developers can enable deep linking at the application-level on the Security Attributes page in Shared Components or for individual pages in Page Designer.

About Determining Whether to Include Authentication

Learn about determining whether to include application authentication.

As you create your application, you must determine whether to include authentication. Options include:

See Also: