Use query parameters instead, it is much safer than including values ββin the query itself. Here is an example from the GAE documentation:
Query query = pm.newQuery("select from Employee " + "where lastName == lastNameParam " + "order by hireDate desc " + "parameters String lastNameParam"); List<Employee> results = (List<Employee>) query.execute("Smith");
source share