Quantcast
Channel: Active questions tagged javascript - Stack Overflow
Viewing all articles
Browse latest Browse all 139893

Sequelize: escape string in a literal string

$
0
0

I can use literal in Sequelize to manually build a SQL query part:

sequelize.literal(`"foo".bar ILIKE '%baz%'`)

But if I want to add a var in this literal block, I now introduce SQL injection vulnerability:

sequelize.literal(`"foo".name ILIKE '%${myVar}%'`)

Is there a Sequelize way to protect variables in literal blocks?


Viewing all articles
Browse latest Browse all 139893

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>