# Dashboard and MS SQL database - number and text input nodes

**URL:** <https://discourse.nodered.org/t/dashboard-and-ms-sql-database-number-and-text-input-nodes/55696>\
**Category:** Dashboard\
**Tags:** database\
**Created:** [25 December 2021 22:03 UTC](https://discourse.nodered.org/t/dashboard-and-ms-sql-database-number-and-text-input-nodes/55696 "2021-12-25T22:03:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Naz](https://avatars.discourse-cdn.com/v4/letter/n/e99b99/32.png) [@Naz](https://discourse.nodered.org/u/Naz)\
**Post date:** [25 December 2021 22:03 UTC](https://discourse.nodered.org/t/dashboard-and-ms-sql-database-number-and-text-input-nodes/55696/1 "2021-12-25T22:03:14Z")

</div>

Hi I am very new to node-red. Im testing something with MS SQL.

I made a dashboard with numeric and text input. (User\_ID,First\_Name,Last\_Name) .

I want it to insert the information into MS SQL.

So I was wondering what is the easiest way to do this ? Can I somehow use the name of my inputs and tell it that's my value when I do a insert?

What I have been trying is connecting the input nodes to a button called Done. When I press the button its sends it to a function node that's processing it and is connected to MS SQL node. Haven't got it to work yet.

Using inject nodes works great so I know my database is working but the point is I want the data from the input from dashboard.

My function looks like this:

msg.topic="INSERT INTO [Test\_03].[dbo].[User\_Name] (User\_ID,First\_Name,Last\_Name) VALUES ('" + msg.payload.User\_ID + "','" + msg.payload.First\_Name + "','" + msg.payload.Last\_Name + "')";  
return msg;

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/1/0/105b898431138408bf20889c0c595546b388b1c9.png)

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [25 December 2021 23:07 UTC](https://discourse.nodered.org/t/dashboard-and-ms-sql-database-number-and-text-input-nodes/55696/2 "2021-12-25T23:07:53Z")

</div>

Hi Naz.

Firstly, one thing to realise is that messages NEVER arrive at the same time. So where you have user\_id, first\_name and last\_name linked to a done button - this is never going to work.

Secondly, you risk [sql injection](https://www.imperva.com/learn/application-security/sql-injection-sqli/#:~:text=SQL%20injection%2C%20also%20known%20as,lists%20or%20private%20customer%20details.) by concatinating strings to generate SQL Queries.

To simplify user input and to avoid SQL Injection, use the `ui_form` - it has sends all values entered in one `msg`. Also, use `node-red-contrib-mssql-plus` as it allows you to use parameters (that negate SQL injection)

Example...  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/e/2/e247da7d6c8731fc0aac316ae973a237e44052ce.png)

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/3/6/36e62c906cff18f1dad5736eb27d5bc3bf3fb9b8.png)

![WcueduFvDl](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/a/b/abf89ef898604558995b23f12a3b0a2c42e5e0d6.gif)

* * *

> [@Naz](#):
>
> I am very new to node-red.

I recommend every new user watches this playlist: [Node-RED Essentials](https://www.youtube.com/playlist?list=PLyNBB9VCLmo1hyO-4fIZ08gqFcXBkHy-6). The videos are done by the developers of node-red. They're nice & short and to the point. You will understand a whole lot more in about 1 hour. A small investment for a lot of gain.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [25 December 2021 23:19 UTC](https://discourse.nodered.org/t/dashboard-and-ms-sql-database-number-and-text-input-nodes/55696/3 "2021-12-25T23:19:07Z")

</div>

If you dont want to use the `ui_form` then you need to store the individual values entered and recover them when the done button is pressed e.g....

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/d/6dd235efd1bd76b22921da7b8bc8e3730d5ba226.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [10 January 2022 01:08 UTC](https://discourse.nodered.org/t/dashboard-and-ms-sql-database-number-and-text-input-nodes/55696/5 "2022-01-10T01:08:35Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
