When you want to use user generated content in the SQL, it with done with parameters. For example for searching user with the name aminadav you should do:
var username = 'aminadav';
var querystring = 'SELECT name, email from users where name = ?';
connection.query(querystring, [username], functi...