te')); return $arr; } /* 遍历用户所有主题 * @param $uid 用户ID * @param int $page 页数 * @param int $pagesize 每页记录条数 * @param bool $desc 排序方式 TRUE降序 FALSE升序 * @param string $key 返回的数组用那一列的值作为 key * @param array $col 查询哪些列 */ function thread_tid_find_by_uid($uid, $page = 1, $pagesize = 1000, $desc = TRUE, $key = 'tid', $col = array()) { if (empty($uid)) return array(); $orderby = TRUE == $desc ? -1 : 1; $arr = thread_tid__find($cond = array('uid' => $uid), array('tid' => $orderby), $page, $pagesize, $key, $col); return $arr; } // 遍历栏目下tid 支持数组 $fid = array(1,2,3) function thread_tid_find_by_fid($fid, $page = 1, $pagesize = 1000, $desc = TRUE) { if (empty($fid)) return array(); $orderby = TRUE == $desc ? -1 : 1; $arr = thread_tid__find($cond = array('fid' => $fid), array('tid' => $orderby), $page, $pagesize, 'tid', array('tid', 'verify_date')); return $arr; } function thread_tid_delete($tid) { if (empty($tid)) return FALSE; $r = thread_tid__delete(array('tid' => $tid)); return $r; } function thread_tid_count() { $n = thread_tid__count(); return $n; } // 统计用户主题数 大数量下严谨使用非主键统计 function thread_uid_count($uid) { $n = thread_tid__count(array('uid' => $uid)); return $n; } // 统计栏目主题数 大数量下严谨使用非主键统计 function thread_fid_count($fid) { $n = thread_tid__count(array('fid' => $fid)); return $n; } ?>javascript - How to create prepared statements in Sequelize? - Stack Overflow
最新消息:雨落星辰是一个专注网站SEO优化、网站SEO诊断、搜索引擎研究、网络营销推广、网站策划运营及站长类的自媒体原创博客

javascript - How to create prepared statements in Sequelize? - Stack Overflow

programmeradmin3浏览0评论

First is it possible, I think it should be as they're safer than raw queries and prevent sql injection.

But there is literally nothing I can find in documentation.

sequelize.prepare <- doesn't exist

sequelize.query <- exists

First is it possible, I think it should be as they're safer than raw queries and prevent sql injection.

But there is literally nothing I can find in documentation.

sequelize.prepare <- doesn't exist

sequelize.query <- exists

Share Improve this question asked Mar 12, 2018 at 19:06 Muhammad UmerMuhammad Umer 18.1k24 gold badges109 silver badges174 bronze badges 1
  • Did you ever get an answer to this? – Shayne Commented Feb 16, 2024 at 8:24
Add a ment  | 

1 Answer 1

Reset to default 15

Never Mind, The sequelize.query has an option called replacements that is escaped automatically.

replacements are escaped and inserted into the query by sequelize before the query is sent to the database

sequelize.query('SELECT * FROM users WHERE name LIKE :search_name ',
  { replacements: { search_name: 'ben%'  }, type: sequelize.QueryTypes.SELECT }
).then(projects => {
  console.log(projects)
})
发布评论

评论列表(0)

  1. 暂无评论