Skip to content

script.escape ​

Escapes a string so it can be used in a SQL query. Use it on values from users, such as prompt answers.

It escapes quotes, backslashes and control characters with a backslash, as MySQL and MariaDB expect. Other databases, such as SQL Server and PostgreSQL, escape differently, so use parameters with those.

Prefer parameterised queries

Where you can, pass values as parameters instead, such as with DatasourceClient's ? placeholders. The database then treats each value as data, never as part of the SQL, so it's safe whatever the value contains. Escaping depends on catching every special character, and it's easy to miss a value. Use script.escape where parameters aren't available, such as with script.processUpdateQuery.

js
script.escape(inputStr)

Parameters ​

ParameterTypeDescription
inputStrstringThe string to escape.

Returns ​

string

The escaped string.

Examples ​

js
const valueForSQL = script.escape("It's usually not ok to have a single quote in a SQL statement.");
text
It\'s usually not ok to have a single quote in a SQL statement.