# Pass data throught a button to SQL Table

**URL:** <https://discourse.nodered.org/t/pass-data-throught-a-button-to-sql-table/59649>\
**Category:** General\
**Created:** [10 March 2022 10:30 UTC](https://discourse.nodered.org/t/pass-data-throught-a-button-to-sql-table/59649 "2022-03-10T10:30:21Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [10 March 2022 10:53 UTC](https://discourse.nodered.org/t/pass-data-throught-a-button-to-sql-table/59649/3 "2022-03-10T10:53:51Z")

</div>

Here is a solution (one of many on the forum)

It uses a form so that all dashboard inputs arrive at the SQL node at the same time.

> [@Dashboard and MS SQL database - number and text input nodes](https://discourse.nodered.org/t/dashboard-and-ms-sql-database-number-and-text-input-nodes/55696/2):
>
> Hi Naz. Firstly, one thing to realise is that messages NEVER arrive at the same time. So where you have user\_id, first\_name and last\_name linked to a done button - this is never going to work. Secondly, you risk [sql injection](https://www.imperva.com/learn/application-security/sql-injection-sqli/#:~:text=SQL%20injection%2C%20also%20known%20as,lists%20or%20private%20customer%20details.) by concatinating strings to generate SQL Queries. To simplify user input and to avoid SQL Injection, use the ui\_form - it has sends all values entered in one msg. Also, use node-red-contrib-mssql-plus as it allows you to use parameters (that negate SQL injection) Exampl…

If you are using separate UI elements, then you will need to either use a JOIN node (to make a single object with all the user values in) OR use flow/global context to store the users input.

---

_[View the full topic](https://discourse.nodered.org/t/pass-data-throught-a-button-to-sql-table/59649)._
