var app = require('express')(); app.get('/user/:id', function(req, res) { let id = req.params.id; id = id.replace(/<|>|&|"/g, ""); // GOOD let userHtml = `
${getUserName(id) || "Unknown name"}
`; // ... res.send(prefix + userHtml + suffix); });