script.escape
Escapes a string so it can be used in a SQL query. Use it on values from users, such as prompt answers.
It escapes quotes, backslashes and control characters with a backslash, as MySQL and MariaDB expect. Other databases, such as SQL Server and PostgreSQL, escape differently, so use parameters with those.
Prefer parameterised queries
Where you can, pass values as parameters instead, such as with DatasourceClient's ? placeholders. The database then treats each value as data, never as part of the SQL, so it's safe whatever the value contains. Escaping depends on catching every special character, and it's easy to miss a value. Use script.escape where parameters aren't available, such as with script.processUpdateQuery.
js
script.escape(inputStr)Parameters
| Parameter | Type | Description |
|---|---|---|
inputStr | string | The string to escape. |
Returns
stringThe escaped string.
Examples
js
const valueForSQL = script.escape("It's usually not ok to have a single quote in a SQL statement.");text
It\'s usually not ok to have a single quote in a SQL statement.