This may seem like a dumb question, but I dont understand why you would write SQL queries in your JavaScript files. Can’t JavaScript files be seen by the client? So if you have something like:
var mysql = require('mysql');
var connection = mysql.createConnection({
host : 'localhost',
user : 'foo',
password : 'bar',
database : 'db'
});
connection.connect();
connection.query('SELECT * from table', function(err, rows, fields) {
if (!err)
console.log('The query returned ' + rows);
else
console.log('An error occurred.');
});
// rest of js code
Isn’t this a security issue? Someone please educate me.