Skip to main content

escape

@webda/core


Function: escape()

escape<T>(parts, values): WebdaQLString<T>

Defined in: packages/ql/lib/webdaql-string.d.ts:50

Type-aware WebdaQL value escaper. Called by the rewritten output of any template literal that flows into a WebdaQLString<T> parameter:

`name = ${n} AND age = ${a}`

is rewritten by the qlvalidator transformer to:

escape(["name = ", " AND age = ", ""], [n, a])

Each value is escaped according to its runtime type, then concatenated with the surrounding parts to form a parameterised query string that cannot be used to inject grammar. Strings are quoted by the escaping, so the template must not quote the interpolation itself. Queries built at runtime use the same escaping through bind() and ? / :name parameters.

Type Parameters​

T​

T = unknown

Parameters​

parts​

readonly string[] | TemplateStringsArray

the static string fragments from the template literal

values​

readonly unknown[]

the interpolated values to escape and interleave

Returns​

WebdaQLString<T>

a branded WebdaQL query string safe for use with Store.query