Currently, we are passing the raw user input straight into a query(thanks `sqlx` for protecting us from SQL injections);