{"_id":"@scaleleap/pg-format","_rev":"1-42d037f37c069f1f7be1803b8c2f3f55","name":"@scaleleap/pg-format","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@scaleleap/pg-format","version":"1.0.0","description":"A fully typed TypeScript and Node.js implementation of PostgreSQL format() to safely create dynamic SQL queries. SQL identifiers and literals are escaped to help prevent SQL injection.","license":"MIT","author":{"name":"Roman Filippov","email":"roman@scaleleap.com","url":"https://www.scaleleap.com/"},"homepage":"https://github.com/ScaleLeap/pg-format","repository":{"type":"git","url":"git+ssh://git@github.com/ScaleLeap/pg-format.git"},"bugs":{"url":"https://github.com/ScaleLeap/pg-format/issues"},"main":"lib/index.js","scripts":{"prebuild":"npm run clean","build":"tsc --build tsconfig.build.json","clean":"rimraf lib/*","dev":"ts-node-dev --respawn --transpileOnly src","lint":"eslint --ext ts,js src/ test/","lint:fix":"npm run lint -- --fix","semantic-release":"npx @scaleleap/semantic-release-config","start":"ts-node --transpile-only --pretty src","test":"jest","test:watch":"jest --watchAll"},"types":"lib/index.d.ts","devDependencies":{"@scaleleap/utils":"1.9.34","@types/jest":"26.0.23","@types/node":"13.13.51","danger":"10.6.4","jest":"26.6.3","rimraf":"3.0.2","ts-jest":"26.5.5","tsconfigs":"4.0.2","typescript":"4.2.4"},"keywords":["escape","format","pg","pg-escape","pg-format","postgres","postgresql","query","sql injection"],"publishConfig":{"access":"public"},"gitHead":"b895951e668efbc7b3a7abb1f52a995a129ce47f","_id":"@scaleleap/pg-format@1.0.0","_nodeVersion":"14.17.0","_npmVersion":"6.14.13","dist":{"integrity":"sha512-gFkcYMnpeylF2OJ30FsDBjwICB9JTiZ5i3guPwdiBDrJFwIKr+Zk6jwI8Mg22a4FwXn5ezd5cHEFMKqBqBz4RQ==","shasum":"fe001f2615e0faf2f4d17af3e8dc3a90ae575be9","tarball":"https://registry.npmjs.org/@scaleleap/pg-format/-/pg-format-1.0.0.tgz","fileCount":13,"unpackedSize":29559,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgqc+uCRA9TVsSAnZWagAAbu4P/jZC22t09rk5RdCUWb3K\nma7YBJbL6a4A14sLiq3WRkghO7sipyUyN3ZHyZwPKVwPzTJKEoPTE1VTPxRY\nenFyWNoX0LWucgun1CyU5u4gR6rtI3tC0Ei338Ct/XbMcUTpmtUooOV8zEnM\nxeQjD4ltw976PRm1Ld9xT4U3AqdObVaHCgkaaIcyih9d0/x4uCUEI9Fa93z6\nZekbaY8nF1Hn36CG/aZQXtc3hFHtR7MMq24M3dNPhqORypRUTDBL87OZLeJ7\nxeINi0XlQk07JRAG8rgYKN2XOCVQjbFjOc3uo7ReP3AQ+adnUg+w6Bso1c/1\nIVyg9T7O/Hy0WdWaLxi27csbXCCAc4gILp70cT0GesNIDTyNKtyaGt7TKVPC\n8c8UF/JyVswchWMRX6SbPedNljoZ6LAKwnIIawO0G90k+RTB2gCX2zIGDYZf\nIyt7jq91KBipPBf8mgEj/EKNWyGuHrmIs/DqlzM3wPq9ysbKMjcCIgEpweQY\n0+FC4My/kryJ5G/h8z3mgG0Qtyzj9KLKQ+f3r5D6HaUahmR0js4a+S2QPYK6\n1/alMF0rSG5/VP8dXiIhozWGyS3jJNqJy0Yz7wTLv1fwLTrCbG2zmYmz81C5\nDgnnHokki+8vfjO4A4DqyB1qKu3rKnLvXmolAQrv/bcKTWeLcPl8OVuy468r\ncHrK\r\n=BReP\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDmSzrjzqsWK3IYmYV3JCQP1/ADEONUfrXIneCezkOYDgIhAPqy7VxMqAADXxWD1rhwIHk1HcyYMTssme5FJqkcDUy7"}]},"_npmUser":{"name":"scalebot","email":"scale-bot@scaleleap.com"},"directories":{},"maintainers":[{"name":"scalebot","email":"scale-bot@scaleleap.com"},{"name":"moltar","email":"rf@romanfilippov.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/pg-format_1.0.0_1621741485454_0.39594392907885956"},"_hasShrinkwrap":false}},"time":{"created":"2021-05-23T03:44:45.115Z","1.0.0":"2021-05-23T03:44:45.633Z","modified":"2022-04-06T21:59:05.979Z"},"maintainers":[{"name":"scalebot","email":"scale-bot@scaleleap.com"},{"name":"moltar","email":"rf@romanfilippov.com"}],"description":"A fully typed TypeScript and Node.js implementation of PostgreSQL format() to safely create dynamic SQL queries. SQL identifiers and literals are escaped to help prevent SQL injection.","homepage":"https://github.com/ScaleLeap/pg-format","keywords":["escape","format","pg","pg-escape","pg-format","postgres","postgresql","query","sql injection"],"repository":{"type":"git","url":"git+ssh://git@github.com/ScaleLeap/pg-format.git"},"author":{"name":"Roman Filippov","email":"roman@scaleleap.com","url":"https://www.scaleleap.com/"},"bugs":{"url":"https://github.com/ScaleLeap/pg-format/issues"},"license":"MIT","readme":"# 📦 @scaleleap/pg-format\n\nA fully typed TypeScript and Node.js implementation of\n[PostgreSQL format()](http://www.postgresql.org/docs/9.3/static/functions-string.html#FUNCTIONS-STRING-FORMAT)\nto safely create dynamic SQL queries. SQL identifiers and literals are escaped to help prevent SQL\ninjection.\n\nThe behavior is equivalent to\n[PostgreSQL format()](http://www.postgresql.org/docs/9.3/static/functions-string.html#FUNCTIONS-STRING-FORMAT).\nThis package also supports Node buffers, arrays, and objects which is explained [below](#arrobject).\n\nThis package is a derivative of prior art. See Authors or Acknowledgments section below for details.\n\n---\n\nThis package does one, two and three.\n\n## Download & Installation\n\n```sh\nnpm i -s @scaleleap/pg-format\n```\n\n## Example\n\n```ts\nimport { format } from '@scaleleap/pg-format'\nconst sql = format('SELECT * FROM %I WHERE my_col = %L %s', 'my_table', 34, 'LIMIT 10')\nconsole.log(sql); // SELECT * FROM my_table WHERE my_col = 34 LIMIT 10\n```\n\n## API\n\n### format(fmt, ...)\n\nReturns a formatted string based on ```fmt``` which has a style similar to the C function ```sprintf()```.\n\n* ```%%``` outputs a literal ```%``` character.\n* ```%I``` outputs an escaped SQL identifier.\n* ```%L``` outputs an escaped SQL literal.\n* ```%s``` outputs a simple string.\n\n#### Argument position\n\nYou can define where an argument is positioned using ```n$``` where ```n``` is the argument index\nstarting at 1.\n\n```ts\nimport { format } from '@scaleleap/pg-format'\nconst sql = format('SELECT %1$L, %1$L, %L', 34, 'test')\nconsole.log(sql); // SELECT 34, 34, 'test'\n```\n\n### format.config(cfg)\n\nChanges the global configuration. You can change which letters are used to denote identifiers,\nliterals, and strings in the formatted string. This is useful when the formatted string contains a\nPL/pgSQL function which calls [PostgreSQL format()](http://www.postgresql.org/docs/9.3/static/functions-string.html#FUNCTIONS-STRING-FORMAT)\nitself.\n\n```ts\nimport { config } from '@scaleleap/pg-format'\nconfig({\n    pattern: {\n        ident: 'V',\n        literal: 'C',\n        string: 't'\n    }\n})\nconfig() // reset to default\n```\n\n### format.ident(input)\n\nReturns the input as an escaped SQL identifier string. `undefined`, ```null```, and objects will\nthrow an error.\n\n### format.literal(input)\n\nReturns the input as an escaped SQL literal string. ```undefined``` and ```null``` will return\n```'NULL'```;\n\n### format.string(input)\n\nReturns the input as a simple string. ```undefined``` and ```null``` will return an empty string.\nIf an array element is ```undefined``` or ```null```, it will be removed from the output string.\n\n### format.withArray(fmt, array)\n\nSame as ```format(fmt, ...)``` except parameters are provided in an array rather than as function\narguments. This is useful when dynamically creating a SQL query and the number of parameters is\nunknown or variable.\n\n## Node Buffers\n\nNode buffers can be used for literals (```%L```) and strings (```%s```), and will be converted to\n[PostgreSQL bytea hex format](http://www.postgresql.org/docs/9.3/static/datatype-binary.html).\n\n## Arrays and Objects\n\nFor arrays, each element is escaped when appropriate and concatenated to a comma-delimited string.\nNested arrays are turned into grouped lists (for bulk inserts), e.g. `[['a', 'b'], ['c', 'd']]`\nturns into `('a', 'b'), ('c', 'd')`. Nested array expansion can be used for literals (```%L```) and\nstrings (```%s```), but not identifiers (```%I```).\n\nFor objects, ```JSON.stringify()``` is called and the resulting string is escaped if appropriate.\nObjects can be used for literals (```%L```) and strings (```%s```), but not identifiers (```%I```).\nSee the example below.\n\n```ts\nimport { format } from '@scaleleap/pg-format'\n\nconst myArray = [ 1, 2, 3 ]\nconst myObject = { a: 1, b: 2 }\nconst myNestedArray = [['a', 1], ['b', 2]]\n\nlet sql = format('SELECT * FROM t WHERE c1 IN (%L) AND c2 = %L', myArray, myObject)\nconsole.log(sql) // SELECT * FROM t WHERE c1 IN (1,2,3) AND c2 = '{\"a\":1,\"b\":2}'\n\nsql = format('INSERT INTO t (name, age) VALUES %L', myNestedArray)\nconsole.log(sql) // INSERT INTO t (name, age) VALUES ('a', 1), ('b', 2)\n```\n\n## Contributing\n\nThis repository uses [Conventional Commit](https://www.conventionalcommits.org/) style commit messages.\n\n## Authors or Acknowledgments\n\n* [TJ Holowaychuk](https://github.com/tj) for the original\n  [pg-escape](https://github.com/segmentio/pg-escape)\n* [Datalanche, Inc](https://github.com/datalanche/node-pg-format) for\n  [pg-format](https://github.com/datalanche/node-pg-format)\n* [Clint Phillips](https://github.com/cphillips/node-pg-format) for\n  [node-pg-format](https://github.com/cphillips/node-pg-format), a TypeScript port of `pg-format`\n  package. I borrowed most of the TypeScript code from `node-pg-format`.\n* [Roman Filippov](https://github.com/moltar) and\n  [Scale Leap](https://www.scaleleap.com) for this package.\n\n## License\n\nThis project is licensed under the MIT License.\n\n## Badges\n\n[![NPM](https://img.shields.io/npm/v/@scaleleap/pg-format)](https://npm.im/@scaleleap/pg-format)\n[![License](https://img.shields.io/npm/l/@scaleleap/pg-format)](./LICENSE)\n[![GitHub Workflow Status](https://img.shields.io/github/workflow/status/ScaleLeap/pg-format/CI)](https://github.com/ScaleLeap/pg-format/actions)\n[![Codecov](https://img.shields.io/codecov/c/github/scaleleap/typescript-template)](https://codecov.io/gh/ScaleLeap/pg-format)\n[![Snyk](https://img.shields.io/snyk/vulnerabilities/github/scaleleap/typescript-template)](https://snyk.io/test/github/scaleleap/typescript-template)\n[![Semantic Release](https://img.shields.io/badge/%20%20%F0%9F%93%A6%F0%9F%9A%80-semantic--release-e10079.svg)](https://github.com/semantic-release/semantic-release)\n","readmeFilename":"README.md"}