Skip to main content

Collaborate 2011 - Day 4

The fourth day already...starting of with APEX, Tales from the Trenches by Paul Dorsey. Paul presented the results from a number of interviews (via email) he did with APEX users. He picked the people that presented on APEX somewhere (like me) and asked everyone things like, what do you like about the tool, what not, what's easy, what's not etcetera. And he presented the results of all this with his own opinions on top of it. One remarkeble quote of Paul (so don't shoot me, I am just the messenger): "APEX has succeeded, ADF has failed". This based on the "facts" (as Paul sees it) that most ADF projects fail and almost all APEX projects are succesful. Apart from that: The APEX community is growing, while the ADF community stays on the same level - but that probably will change when Fusion Apps will take off. The bottom line of his talk was: there is something way better than all of this and that's my product "Formspider". But alas for Paul, his product fills in some disadvantages of APEX that nobody sees (or even bothers)...but Paul himself.
After this session, Scott Spendolini, David Peake and myself had a talk about it - and some enhancement requests for APEX 4.x. So I missed the session I originally had planned to attend.
Next I went to a session about Oracle VM. With Oracle VM you can run multiple different guests, containing different operating systems and/or database versions on the same hardware. Good for short term labs situations: Easy and quick to set up, run your tests and destroy the VM. The VM can be managed using Oracle Enterprise Manager. O, yeah, did I already mention it was free? It is not similar to something like VirtualBox, because when you use Oracle VM, that VM is the Operating System (and Windows or Unix is just a guest). Great for training, testing, patching, trying out new technology and products. As a result you can apply patches faster and more frequently in production, just because it is easier to test them..
Just before lunch there was a 30 minute session about Dynamic SQL in APEX. Usually only used for reporting. Tip: Use apex_application.debug( ) within the dynamic part to show in debug mode what's been generated. Can make your life much easier. Alas, dynamic SQL doesn't work in Interactive Reports. A solution is using collections (another solution is using pipedlined functions, but the presenter didn't mention that. Getting the column names right might be a bit nasty though, but you can even use a function that returns those column names.
Scott Spendolin presented on Security in APEX. I think I've seen it before, because it sounded all very familiar - but you can't here it often enoough! Scott talked about multiple security issues and several ways to protect you against it: Be aware that the danger comes from within... First, create a "shadow" schema with read only views on views owned by the actual "data" schema. All DML should be executed using procedure calls, so you have to change the processes in the pages (another solution is: create a regular view with instead of triggers that use the API calls). The framework for these calls can be generated automatically within APEX. Be sure to revoke all privileges from the shadow schema (maybe not at first, but certainly in production) - as a side effect you can't use supporting objects anymore, as the schema has no rights to install them. And add system level triggers to prevent dropping objects. Another tip is : Reduce data access using context settings in every query. 
Back to back, Scott had another session about APEX Maturity. He walked us trough the whole history of APEX, from conception until where it is now. Interesting and especially entertaining.
The last timeslot was for my own presentation on building a Plugin for Google Visualizations. As I had noticed that the audience wasn't very mature yet, I had to change it a little on the fly - as only one person in the audience had ever used a plug-in, let alone build one! Afterwards I think I should have taken a complete different direction, by just showing them what a Plug-in can do for you - and skip the build stuff all together. But that's aftertalk. But they where amazed by the updateable Organizational Chart of course...sub-zero!
After all that, and some chilling down, Universal's Island of Adventures was at our disposal! So with no lines at all (instead of the regular 2, 3 + hour waiting lines), we could enter any attraction. And the most spectacular one, without any doubt, is the Harry Potter ride (check it out on YouTube). It's a sort of rollercoaster ride, with movie projection and a ghost house. Never seen something like that. Spiderman was also good (a little "lighter" than Potter), but a combination of a 3D movie and a rollercoaster like ride has it's effects...
2 comments

Popular posts from this blog

Showing a success message after closing a modal dialog

APEX 5 comes with Modal Dialogs out of the box. Very neat. Especially for adding and changing data. And to minimise the number of time a user has to click, it could be useful to add a "Close Dialog" process after the actual data processing. When the data processing fails, the Dialog stays on top showing the error. When data processing runs fine, the Dialog is closed ... without any confirmation. And this might be scary for a shaky user.

So how can we provide the user some feedback? On Page 4 of the Sample Dialog Application you can see one solution: up on a Dialog Closed Event on the parent page it does a redirect to refresh the parent page appending the success message of the "Close Dialog" process. This has two drawbacks. First, it probably refreshes more than necessary. And second, if you're using multiple layers of dialogs (dialogs that open other dialogs) the message appears in the "parent dialog".
As an alternative you could follow these steps: 1…

APEX 5 New Static File Features

In APEX 4 you could upload files - like CSS files, JavaScript files, Images and whatever else you like - into the APEX Repository. When you navigate to Shared Components, there is a Files section that offers three different options:
CSS Files are always uploaded (and changed !) for the whole Workspace. For Images and Static Files (usually JavaScript) you could choose whether they should be available for the whole Workspace or for a specific Application only. And if you had a lot of files - e.g. a lot of images - then you had to go through the upload process one-by-one. But that's usually a one time only thing. If you make changes to the CSS and JavaScript files - and that's a continuous process in development - then you had to delete the existing file and upload the new one. Over and over again. And meanwhile fighting the cache of the webserver and your browser.  And another irritating issue: You couldn't use relative references in your CSS or JavaScript files as they just…

Using LDAP for Authentication and Authorization within APEX

One of my current customers would like to use their LDAP (Microsoft Active Directory) server for authentication and authorization of APEX applications. Of course we tried to set up a standard LDAP Authenication that's available within APEX. But we couldn't get that to work. Maybe it has to do with the fact that the client stored their Users within Groups within Groups within .... . Or maybe it doesn't do a full tree walk in the directory. Or maybe it is just because it is Microsoft - and not Oracle Internet Directory (OID). So we moved to a custom Authentication using the DBMS_LDAP functions (and some examples from the Pro Oracle Application Express book and Tim Hall - a.k.a. Oracle Base).

One of the issues we encountered that we wanted to use the user's login name, like "jdoe" and not his full name ("John Doe"). And the login name is stored in the "sAMAccountName" attribute. But authenticating using just "jdoe" didn't work. …