4 ms·
great to use template lilerals, but any way to use in perpare statement in order to escape sql injection etc type of stuff?
by lowwave 5y ago
great to use template lilerals, but any way to use in perpare statement in order to escape sql injection etc type of stuff?
- lowwave 5y agoJust saw this on the page: >Parameters are automatically extracted and handled by the database so that SQL injection isn't possible. No special handling is necessary, simply use tagged template literals as usual. Dynamic queries and query building can be seen in the next section. // todo this is great! Can't wait to give a try.