Oracle Application Express (MOSC)

MOSC Banner

About APEX_AUTHENTICATION.LOGOUT

edited Jul 2, 2025 9:14AM in Oracle Application Express (MOSC) 1 commentAnswered

Hi there. I have a question about APEX. When we develop a web application using APEX with a custom login scheme, the default sign-out button uses a URL that references to &LOGOUT_URL. This URL looks like:
...apex_authentication.logout?p_app_id=xxx&p_session_id=xxxx.

My question is:
Can a third party change the value of p_session_id?
Or does this URL have any risk of SQL injection?

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center