1// Escape values:
2
3let escaped = mysql.escape('myString');
4
5// or
6
7mysql.query(
8 "SELECT * FROM `table` WHERE `str1`=? AND `str2`=?",
9 ['myString1', 'myString2'],
10 (err, result)=>{}
11);
12
13// Escape identifiers:
14
15mysql.query(
16 "SELECT * FROM ??", // note the double ?
17 ['tablename'],
18 (err, result)=>{}
19);