Internet Features   «Prev  Next»

Lesson 8Internet Applications and Oracle: Module Conclusion
ObjectiveConnect the module's concepts to design choices for connectivity, multimedia, Java, identity, and middleware in Oracle AI Database 26ai applications.

Oracle AI Database 26ai Internet Applications: Module Conclusion

This module examined how Oracle AI Database 26ai participates in internet applications. Database drivers connect application code to database services. Web and API tiers receive requests from browsers and mobile clients. Identity systems establish who is making a request, while application rules and database privileges determine which operations are permitted. Media storage and search add further capabilities without changing these basic responsibilities.

The central design task is to connect these components deliberately. A database upgrade does not automatically create REST APIs, configure authentication, pool application connections, or convert an older multimedia application. Each capability has a place in the architecture and an owner responsible for configuring and operating it.

The following review brings together the seven lessons and applies them to a practical application scenario. Use the lesson links to revisit detailed examples and diagrams before making implementation decisions.

1. Choose the Application's Connection Model

Internet and Cloud Connectivity established the difference between connecting directly to Oracle and accessing database-backed web services. A Java application can use Oracle JDBC Thin to communicate with a database service through Oracle Net. Other languages use their corresponding drivers. These connections allow application code to execute SQL, invoke PL/SQL, and manage transactions.

In a two-tier design, the client application communicates directly with the database. In a three-tier design, an application tier stands between presentation clients and database services. A browser typically sends an HTTPS request to that application tier, which obtains a database connection and performs the authorized operation. This arrangement centralizes business logic and connection management.

ORDS provides a REST API option for database-backed operations. It is a Java middle-tier service, with its own deployment and configuration. It can complement a custom application server or provide the API interface required by a particular client. Choosing REST does not eliminate the database connection behind the endpoint.

For either model, identify the database service, network route, credentials, and transport protection. A working browser connection proves only that the browser can reach the web endpoint. The application still needs its own functioning and appropriately protected path to Oracle.

2. Manage Connections and Session State

Connection pooling allows an application to reuse established database connections across requests. Oracle Universal Connection Pool (UCP) is an application-side pool for Java. WebLogic also manages pools through its JDBC data sources. Applications should borrow connections for bounded units of work and return them promptly, with transaction outcomes handled explicitly.

Pool capacity is an application-wide planning decision. Four application instances configured for fifty connections each can potentially consume two hundred connections. Adding instances to improve web-tier throughput can therefore increase pressure on the database. Measure connection waits, request duration, and database utilization before raising pool limits.

Database Resident Connection Pooling (DRCP) operates on the database side and can complement application pooling for suitable workloads. It requires supported client configuration and an available server-side pool. It is distinct from both the Java application pool and Oracle's Java memory pool.

Session reuse also affects correctness. A new HTTP request does not necessarily receive a new database session. Application context, package state, or other session settings may survive between uses unless managed appropriately. Define initialization and reset behavior, and ensure that one user's session state cannot influence another user's request.

3. Separate Multimedia Storage, Processing, and Search

Multimedia Storage and Search explained why photographs, recordings, videos, and documents remain relevant to Oracle applications. The database can associate this content with products, customers, permissions, and transactions. Storing the content, transforming it, and finding related content are different operations.

A persistent BLOB can hold binary media inside the database. A CLOB can hold large character content, such as a transcript. Relational columns and JSON can represent metadata. SecureFiles provides LOB storage capabilities, but encryption and other storage options require the applicable configuration rather than following automatically from the product name.

Alternatively, an application can keep media in object storage and maintain identifiers and metadata in Oracle. This design needs coordinated retention, access, and deletion policies. A database backup protects the database records, but does not automatically back up the externally stored objects. A BFILE likewise refers to an external server-accessible file; it is not a generic cloud-object URL.

Image resizing, format conversion, and video transcoding belong to suitable processing libraries or services. Plan how failed processing jobs are retried, how derived files relate to originals, and how the application distinguishes uploaded content from approved content. These lifecycle questions matter even when the application uses no AI features.

4. Use Vector Search for a Defined Retrieval Task

AI Vector Search adds similarity retrieval through embeddings stored in VECTOR columns. A compatible model generates numerical representations of content, and database queries compare those representations. The embedding pipeline determines what the search can meaningfully retrieve.

For image similarity, stored image embeddings and the query embedding must come from compatible encoders and preprocessing. Text-to-image retrieval requires a model arrangement that puts text and images into a shared embedding space. Matching the number of dimensions is insufficient if the underlying representations are incompatible.

Record model versions and regenerate embeddings when relevant source content or models change. Select an appropriate distance metric and evaluate retrieval quality with representative examples. Exact and approximate search offer different performance and retrieval tradeoffs. Business filters and access rules must still constrain which results the application can return.

For a known product photograph, an ordinary identifier lookup may be the best solution. Vector search becomes useful when the user wants related or semantically similar content. It does not replace the original media, establish access rights, or by itself produce a language-model answer.

5. Recognize Historical interMedia Dependencies

Oracle interMedia: Historical Multimedia Architecture placed the older object-relational approach in context. Oracle interMedia's multimedia features became Oracle Multimedia. That feature was deprecated in Oracle Database 18c and desupported in 19c, when its implementation was removed.

Older applications may still contain references to types such as ORDImage, ORDVideo, and ORDAudio. These references identify dependencies to investigate, not APIs to adopt for Oracle AI Database 26ai. Migration requires preserving media and metadata, identifying processing calls, and assigning those responsibilities to supported components.

Oracle Text has a separate history and remains relevant to text searching. Its continued role should not be confused with the removal of Oracle Multimedia. Similarly, neither ORDS nor AI Vector Search is a complete replacement for every historical multimedia method.

6. Decide Where Java Code Belongs

Java and Oracle AI Database 26ai distinguished an external application JVM from Oracle JVM inside the database. External Java applications connect through JDBC Thin and can deploy or scale independently of the database. They do not require Oracle JVM merely to establish JDBC connections.

Stored Java requires Oracle JVM support in the target environment. A Java call specification exposes a suitable method to SQL or PL/SQL. Server-side internal JDBC accesses the existing database session and transaction locally. It should not be treated as a newly borrowed network connection from an application pool.

Use SQL for set-based operations and declarative constraints where appropriate. PL/SQL suits database-centric transaction logic. External Java suits application services, integration, and processing libraries. Stored Java can be useful for a compatible routine that needs to execute within a database session, after checking its dependencies and permissions.

The Oracle JVM's shared definitions and session-private mutable state are also distinct from application connection management. Moving code into the database changes where its CPU and memory are consumed. Evaluate the complete workload and supported runtime rather than assuming that executing closer to the data always improves performance.

7. Keep Directory Services and Application Identity Distinct

Oracle Unified Directory and Modern Application Identity separated several meanings of the word directory. OUD provides LDAP directory capabilities for identities and attributes. Oracle Internet Directory is a separate product. A SQL DIRECTORY object names a server-side filesystem location, while Oracle Net directory naming resolves connection information.

These roles do not make an LDAP directory a media repository or a REST service. An application that needs LDAP lookups may retain that requirement while introducing federated web sign-in. The appropriate design depends on its identity sources, supported integrations, and required protocols.

OCI IAM identity domains provide application identity capabilities, including OpenID Connect and OAuth 2.0. OpenID Connect supports sign-in; OAuth 2.0 provides a framework for access authorization. An ID token should not simply be substituted for an API access token.

Keep authorization boundaries explicit. OCI policies govern cloud resources, application and API rules govern permitted operations, and database privileges govern SQL access. A successful sign-in or accepted token does not automatically grant privileges at every layer. Configure the required mappings and validation for each integration.

8. Select Web Tools by Their Responsibilities

Oracle 26ai Tools for Internet Applications reviewed complementary tools. ORDS exposes selected database operations over HTTP. Oracle APEX supports database-backed forms, reports, and workflows using a browser, web tier, and database engine. JSON-relational duality views provide a document representation of relational data.

Duality views preserve a relational foundation while supporting document-oriented interaction. Their definitions determine permitted changes. Applications using supported ETAG checks can detect stale document updates, but must still handle conflicts. The database does not automatically merge every competing edit into the intended business result.

Other capabilities serve specific requirements. SQL property graphs support relationship queries. MongoDB-compatible access requires checking the documented compatibility for the selected deployment. True Cache and distributed database designs address particular scaling needs. Introduce these components when measurements and application requirements justify their operational cost.

9. Place WebLogic and OCI in the Architecture

Oracle WebLogic Server and OCI Integration explained the application server's role in running enterprise Java applications. WebLogic provides services such as transactions, messaging, application security, and JDBC pooling. ORDS can complement those services by exposing selected database-backed APIs.

Middleware versions matter independently of the database release. WebLogic 14.1.2 supports Jakarta EE 8, while 15.1.1 supports Jakarta EE 9.1. The enterprise API namespace change can require application and library updates. Check the certified combination of middleware, database, driver, JDK, and operating system before deployment.

OCI offers application hosting and several database service choices. Moving an application to OCI does not automatically modernize its code or remove patching and recovery responsibilities. Decide which responsibilities the selected service handles and which remain with the application and database teams. Networking, credentials, monitoring, and application updates still require ownership.

Putting the Lessons Together: A Product Catalog

Consider a web store that displays products, accepts purchases, and allows employees to maintain product photographs. A browser communicates with an HTTPS application or API tier. The application validates requests and obtains a pooled database connection to read product details or perform a transaction.

The following choices form one possible design. They are alternatives to assess, rather than a requirement to deploy every product covered in the module.

Applying Module 6 to a database-backed product catalog
RequirementPossible implementationDesign question
Product queries and purchasesApplication service using JDBC and transactional SQL or PL/SQLWhere are validation, authorization, and commit decisions enforced?
Mobile APIConfigured ORDS endpointsWhich operations may each client perform?
Employee maintenance interfaceAPEX or a custom web applicationHow are employee roles and editing rights assigned?
Product photographsSecureFiles BLOBs or object storageHow are access, recovery, and deletion coordinated?
Visual product discoveryCompatible image embeddings and AI Vector SearchHow will relevance and permitted results be evaluated?
Federated sign-inOCI IAM identity domains or another supported providerHow does identity map to application permissions?

Suppose an employee replaces a photograph. The application verifies permission, validates the upload, and records the new content version. A processing job creates any required thumbnail and embedding. The application keeps the old version available or marks the new version pending until required processing succeeds. This makes failure handling part of the content lifecycle.

If the photograph resides in object storage, the design must also handle partial completion between the object update and database metadata update. A database transaction does not automatically include a remote storage API call. Define retry, reconciliation, and cleanup behavior so a failed request does not leave inaccessible content or broken references.

For a purchase, prioritize transaction correctness over the number of technologies involved. Prevent unauthorized changes, apply inventory and pricing rules consistently, and handle duplicate or retried requests. Search results can help a customer find a product, but the purchase transaction must validate the current business data.

Operational Review Before Deployment

Review the architecture as a complete request path. Identify how a user signs in, how an operation is authorized, which service executes it, which database identity is used, and where data is stored. This connects development decisions with the DBA's responsibility for reliable database service.

Private network access, encrypted transport, and storage encryption address different concerns. Protect each connection and storage location appropriately. A managed service can reduce specific administrative tasks, but the application team still owns its business rules and the permissions granted to users.

Module Completion Review

You should now be able to explain why a browser API request differs from a JDBC connection, how application pooling differs from DRCP, and why stored Java has a different execution context from external Java. You should also be able to select a media storage approach and identify when metadata queries, text search, or vector similarity retrieval fit the requirement.

For identity and middleware, you should be able to distinguish LDAP directories, application sign-in, API authorization, database privileges, and WebLogic runtime services. Revisit the linked lessons where a boundary remains unclear. A sound Oracle AI Database 26ai application follows from assigning each responsibility to an appropriate component and verifying how the components work together.

Oracle Documentation


SEMrush Software 8 SEMrush Banner 8