* using prepared statements for sql query for fixing sql injection * returning error in getChat instead of logging