never escape anything, either
just hand my users a raw SQL connection
https://news.ycombinator.com/item?id=44677515