4 ms·
PgTyped doesn't include a query executor. It transforms a query and its parameters into a format of parametrized query+parameter bindings, which are then sent i
by alde 7y ago
PgTyped doesn't include a query executor. It transforms a query and its parameters into a format of parametrized query+parameter bindings, which are then sent into a Postgres DB driver of your choice.
A proper DB driver sends the query+parameter bindings pair to the DB. This means that the actual parameter substitution is done on the Postgres server and so SQL injections are prevented on the DB server side.
The driver we recommend and use is node-postgres. It does support parametrized query passing.