That works fine as long as you never need security or robust application logic. Somebody with CURL could really mess up your day.
* abstract away the actual tables behind views, so users don't have direct access to the tables, and you can still modify your tables
* add a table-api to abstract away direct crud actions on your data. Table api's are 3G plsql modules that contains business logic to validate and update date (in the database).
* use vpd (virtual private database) to automatically rewrite queries to include security rules (user and rbac security handled by the database)
* have multiple database object owners (scheme) to split up the database object into different modules. Never use scheme owners to access database from your client as a regular app user.