ES2015 标记的模板字符串用于准备 SQL 语句,可与 `pg`,`MySQL`,`sqlite` 和 `oracledb` 兼容
ES2015 标记的模板字符串用于准备 SQL 语句,可与 `pg`,`MySQL`,`sqlite` 和 `oracledb` 兼容
ES2015 tagged template string for preparing SQL statements.
npm install sql-template-tag --save
…
Accepts an array of values or SQL, and returns SQL with the values joined together using the separator.
const query = join([1, 2, 3]);
query.sql; //=> "?,?,?"
query.values; //=> [1, 2, 3]
Tip: You can set the second argument to change the join separator, for example:
join(
[sql`first_name LIKE ${firstName}`, sql`last_name LIKE ${lastName}`],
" AND ",
); // => "first_name LIKE ? AND last_name LIKE ?"
Accepts a string and returns a SQL instance, useful if you want some part of the SQL to be dynamic.
raw("SELECT"); // == sql`SELECT`
Do not accept user input to raw, this will create a SQL injection vulnerability.
Simple placeholder value for an empty SQL string. Equivalent to raw("").
Accepts an array of arrays, and returns the SQL with the values joined together in a format useful for bulk inserts.
const query = sql`INSERT INTO users (name) VALUES ${bulk([
["Blake"],
["Bob"],
["Joe"],
])}`;
query.sql; //=> "INSERT INTO users (name) VALUES (?),(?),(?)"
query.values; //=> ["Blake", "Bob", "Joe"]
This package "just works" with pg, mysql, sqlite and oracledb.
mssql.query(query.strings, ...query.values);
The default value is unknown to support every possible input. If you want stricter TypeScript values you can create a new sql template tag function.
import { Sql } from "sql-template-tag";
type SupportedValue =
| string
| number
| SupportedValue[]
| { [key: string]: SupportedValue };
function sql(
strings: ReadonlyArray,
...values: Array
) {
return new Sql(strings, values);
}
Some other modules exist that do something similar:
sql-template-strings: promotes mutation via chained methods and lacks nesting SQL statements. The idea to support sql and text properties for dual mysql and pg compatibility came from here.pg-template-tag: missing TypeScript and MySQL support. This is the API I envisioned before writing this library, and by supporting pg only it has the ability to dedupe values.MIT
暂无开放 Issues,或尚未同步最近议题。