To use MySQL in an Express app, set up a connection, run queries securely, and handle errors properly. First, install MySQL and create a database. Next, install the mysql package and configure the connection using a db.js file. Then, use parameterized queries in routes to prevent SQL injection. Additionally, handle errors explicitly in callbacks or with try-catch blocks. Optionally, wrap queries in promises for cleaner async/await code. Finally, always test edge cases and log errors for debugging.
If you're building a Node.js app with Express and want to use MySQL as your database, the setup is straightforward once you know the flow. The main pieces involve connecting your Express app to the MySQL server, running queries, and handling them properly—especially avoiding SQL injection.

Setting Up MySQL in Your Express App
First, make sure you have a MySQL server running locally or remotely. You can install MySQL via tools like XAMPP or directly from the MySQL website. Once it's up, create a new database and table that your Express app will interact with.

In your Node.js project, install the MySQL package:
npm install mysql
Then, set up a connection object in your app (usually in a db.js
or similar config file):

const mysql = require('mysql'); const connection = mysql.createConnection({ host: 'localhost', user: 'root', password: '', database: 'myapp_db' }); connection.connect((err) => { if (err) throw err; console.log('MySQL connected...'); }); module.exports = connection;
This sets up a basic connection. Some people prefer using connection pools for better performance, especially under heavy load. That’s something you might want to explore later.
Querying the Database from Express Routes
Once connected, you’ll want to run SELECT, INSERT, UPDATE, DELETE statements from your routes.
Let’s say you have a /users
route that fetches all users:
const express = require('express'); const router = express.Router(); const db = require('./db'); router.get('/users', (req, res) => { let sql = 'SELECT * FROM users'; db.query(sql, (err, results) => { if (err) throw err; res.json(results); }); });
You can also pass values dynamically, like inserting a new user:
router.post('/users', (req, res) => { let newUser = { name: 'John Doe', email: 'john@example.com' }; let sql = 'INSERT INTO users SET ?'; db.query(sql, newUser, (err, result) => { if (err) throw err; res.send('User added...'); }); });
- Always use parameterized queries (
?
) when passing dynamic data. - Avoid concatenating values into SQL strings to prevent SQL injection.
- Use
.query()
method with proper placeholders.
This way, your code stays safe and readable.
Handling Errors and Edge Cases
Working with databases means things can go wrong—connection issues, query errors, missing rows, etc.
Some common issues include:
- Forgetting to escape input values
- Typos in column or table names
- Not closing connections (if using single connection)
- Trying to access rows that don’t exist
A good practice is to wrap your queries in try-catch blocks (especially when using async/await), or at least handle errors explicitly in callbacks.
For example:
db.query('SELECT * FROM users WHERE id = ?', [req.params.id], (err, results) => { if (err) { console.error(err); return res.status(500).send('Database error'); } if (results.length === 0) { return res.status(404).send('User not found'); } res.json(results[0]); });
Also, logging errors helps debug faster. Don’t just throw or ignore them unless you’re sure.
Using Promises or Async/Await (Optional but Cleaner)
If you're using a newer version of Node.js, consider wrapping your queries in promises or using async/await syntax for cleaner code.
Here’s how you can do it:
const util = require('util'); db.query = util.promisify(db.query).bind(db); // Then inside an async function try { const results = await db.query('SELECT * FROM users'); res.json(results); } catch (err) { res.status(500).send(err); }
It makes your code easier to read and maintain, especially when dealing with multiple queries in sequence.
That’s basically it. It’s not complicated once you get the basics down—connect, query, handle errors, and optionally clean up with async patterns. Just remember to keep your queries secure and always test edge cases.
The above is the detailed content of mysql tutorial for Node.js and Express. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undress AI Tool
Undress images for free

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

The most direct way to connect to MySQL database is to use the command line client. First enter the mysql-u username -p and enter the password correctly to enter the interactive interface; if you connect to the remote database, you need to add the -h parameter to specify the host address. Secondly, you can directly switch to a specific database or execute SQL files when logging in, such as mysql-u username-p database name or mysql-u username-p database name

Character set and sorting rules issues are common when cross-platform migration or multi-person development, resulting in garbled code or inconsistent query. There are three core solutions: First, check and unify the character set of database, table, and fields to utf8mb4, view through SHOWCREATEDATABASE/TABLE, and modify it with ALTER statement; second, specify the utf8mb4 character set when the client connects, and set it in connection parameters or execute SETNAMES; third, select the sorting rules reasonably, and recommend using utf8mb4_unicode_ci to ensure the accuracy of comparison and sorting, and specify or modify it through ALTER when building the library and table.

MySQL supports transaction processing, and uses the InnoDB storage engine to ensure data consistency and integrity. 1. Transactions are a set of SQL operations, either all succeed or all fail to roll back; 2. ACID attributes include atomicity, consistency, isolation and persistence; 3. The statements that manually control transactions are STARTTRANSACTION, COMMIT and ROLLBACK; 4. The four isolation levels include read not committed, read submitted, repeatable read and serialization; 5. Use transactions correctly to avoid long-term operation, turn off automatic commits, and reasonably handle locks and exceptions. Through these mechanisms, MySQL can achieve high reliability and concurrent control.

The setting of character sets and collation rules in MySQL is crucial, affecting data storage, query efficiency and consistency. First, the character set determines the storable character range, such as utf8mb4 supports Chinese and emojis; the sorting rules control the character comparison method, such as utf8mb4_unicode_ci is case-sensitive, and utf8mb4_bin is binary comparison. Secondly, the character set can be set at multiple levels of server, database, table, and column. It is recommended to use utf8mb4 and utf8mb4_unicode_ci in a unified manner to avoid conflicts. Furthermore, the garbled code problem is often caused by inconsistent character sets of connections, storage or program terminals, and needs to be checked layer by layer and set uniformly. In addition, character sets should be specified when exporting and importing to prevent conversion errors

CTEs are a feature introduced by MySQL8.0 to improve the readability and maintenance of complex queries. 1. CTE is a temporary result set, which is only valid in the current query, has a clear structure, and supports duplicate references; 2. Compared with subqueries, CTE is more readable, reusable and supports recursion; 3. Recursive CTE can process hierarchical data, such as organizational structure, which needs to include initial query and recursion parts; 4. Use suggestions include avoiding abuse, naming specifications, paying attention to performance and debugging methods.

MySQL query performance optimization needs to start from the core points, including rational use of indexes, optimization of SQL statements, table structure design and partitioning strategies, and utilization of cache and monitoring tools. 1. Use indexes reasonably: Create indexes on commonly used query fields, avoid full table scanning, pay attention to the combined index order, do not add indexes in low selective fields, and avoid redundant indexes. 2. Optimize SQL queries: Avoid SELECT*, do not use functions in WHERE, reduce subquery nesting, and optimize paging query methods. 3. Table structure design and partitioning: select paradigm or anti-paradigm according to read and write scenarios, select appropriate field types, clean data regularly, and consider horizontal tables to divide tables or partition by time. 4. Utilize cache and monitoring: Use Redis cache to reduce database pressure and enable slow query

To design a reliable MySQL backup solution, 1. First, clarify RTO and RPO indicators, and determine the backup frequency and method based on the acceptable downtime and data loss range of the business; 2. Adopt a hybrid backup strategy, combining logical backup (such as mysqldump), physical backup (such as PerconaXtraBackup) and binary log (binlog), to achieve rapid recovery and minimum data loss; 3. Test the recovery process regularly to ensure the effectiveness of the backup and be familiar with the recovery operations; 4. Pay attention to storage security, including off-site storage, encryption protection, version retention policy and backup task monitoring.

TooptimizecomplexJOINoperationsinMySQL,followfourkeysteps:1)EnsureproperindexingonbothsidesofJOINcolumns,especiallyusingcompositeindexesformulti-columnjoinsandavoidinglargeVARCHARindexes;2)ReducedataearlybyfilteringwithWHEREclausesandlimitingselected
