永遠不要直接向查詢中添加外部輸入(搜索“SQL注入”)。 相反,請使用mysql庫提供的轉義方法: const { sender, receiver, message, ad_id, category_id } = data;const sql = `INSERT INTO tbl_user_chats (sender,receiver,message,ad_id,category_id) VALUES (?, ?, ?, ?, ?)`;con.query(sql, [ sender, receiver, message, ad_id, category_id ], ...)