I need help implementing parameterized queries to prevent SQL injection in my Node.js app. What's the best practice with PostgreSQL?