# Unable to inject SQL query

**URL:** <https://discourse.nodered.org/t/unable-to-inject-sql-query/79520>\
**Category:** General\
**Tags:** database, docker\
**Created:** [1 July 2023 08:38 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520 "2023-07-01T08:38:13Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kamiz](https://avatars.discourse-cdn.com/v4/letter/k/e274bd/32.png) [@Kamiz](https://discourse.nodered.org/u/Kamiz)\
**Post date:** [1 July 2023 08:38 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520/1 "2023-07-01T08:38:13Z")

</div>

Hi,  
I want to perform an SQL query against a database (MariaDB).  
As soon as I configure a plugin (_node-red-mysql-r2_ for example), I cannot deploy my flow if I have an SQL query in my inject node _(deploy failed: forbidden_). I didn't see anything about these errors in the logs (even in trace mode).

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/5/5/55372256d45fcd529560884a503ef773c97e2ebd.png)

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/0/2/02b4323b596d8a2be9e6a79dd08b0918a4620e9d.png)

When I delete the plugin configuration (Global Configuration Nodes) or if I delete msg.topic from the ijnect node, I can deploy the flow again.

If I make a very basic request, like _"SELECT \* FROM USERS;"_ then I can deploy my flow.

_Version: 3.0.2_  
_Environment: Docker_

I really don't understand what's going on, do you have an idea ?

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [1 July 2023 09:06 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520/2 "2023-07-01T09:06:57Z")

</div>

Almost certainly it would be better to use node-red-node-mysql. not least because the maintainers are also the authors of Node-red.

You have to setup Mariadb to allow connections from other machines. Maybe this is also true for connections from other Docker containers on the same machine.

---

<div class="post-metadata">

**Author:** ![Kamiz](https://avatars.discourse-cdn.com/v4/letter/k/e274bd/32.png) [@Kamiz](https://discourse.nodered.org/u/Kamiz)\
**Post date:** [1 July 2023 09:57 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520/3 "2023-07-01T09:57:38Z")

</div>

I just used _node-red-node-mysql_, but the problem is exactly the same.  
As soon as I create my inject node with my SQL query, it is impossible to save the flow

I confirm that I can connect to the database from another machine and that the request returns a valid result :

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/b/9/b9aaf2891ee7859649ee3a25a3aa9293c6e957dc.png)

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [1 July 2023 10:21 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520/4 "2023-07-01T10:21:32Z")

</div>

What exactly happens when you try to deploy?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [1 July 2023 10:25 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520/5 "2023-07-01T10:25:40Z")

</div>

Also repeat the exercise but using the standard node. Export the the nodes and paste the export here. Then we can try it.

Configure the inject to not inject automatically. Does it still fail to deploy, or is it when you click the inject that it fails?

---

<div class="post-metadata">

**Author:** ![Kamiz](https://avatars.discourse-cdn.com/v4/letter/k/e274bd/32.png) [@Kamiz](https://discourse.nodered.org/u/Kamiz)\
**Post date:** [1 July 2023 11:25 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520/6 "2023-07-01T11:25:12Z")

</div>

Here the code:

```auto
[
    {
        "id": "fcb9da7f7a9651c5",
        "type": "tab",
        "label": "SQL",
        "disabled": false,
        "info": "",
        "env": []
    },
    {
        "id": "80fc3bf2aa84e7d1",
        "type": "inject",
        "z": "fcb9da7f7a9651c5",
        "name": "",
        "props": [],
        "repeat": "",
        "crontab": "",
        "once": false,
        "onceDelay": 0.1,
        "topic": "",
        "x": 590,
        "y": 220,
        "wires": [
            [
                "3f3657dccbad3463"
            ]
        ]
    },
    {
        "id": "3f3657dccbad3463",
        "type": "mysql",
        "z": "fcb9da7f7a9651c5",
        "mydb": "bc82281c113049b7",
        "name": "",
        "x": 800,
        "y": 220,
        "wires": [
            [
                "9b778df266405d0c"
            ]
        ]
    },
    {
        "id": "9b778df266405d0c",
        "type": "debug",
        "z": "fcb9da7f7a9651c5",
        "name": "debug 10",
        "active": true,
        "tosidebar": true,
        "console": false,
        "tostatus": false,
        "complete": "false",
        "statusVal": "",
        "statusType": "auto",
        "x": 1000,
        "y": 200,
        "wires": []
    },
    {
        "id": "bc82281c113049b7",
        "type": "MySQLdatabase",
        "name": "",
        "host": "mariadb.local",
        "port": "3306",
        "db": "homeassistant",
        "tz": "",
        "charset": "UTF8",
        "credentials": {}
    }
]

```

Try to add _msg.topic_ into the inject node with these value:

```auto
SELECT table_schema "homeassistant", sum( data_length + index_length ) / 1024 / 1024 "Data Base Size in MB" FROM information_schema.TABLES GROUP BY table_schema;

```

.. and then deploy the flow. if it's like me, you're going to have this error pop-up that will appear:  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/d/6/d67d4a5cef8fed146d2386f1bfb443712053465b.png)

Even if i remove the link between the inject and the sql node, i can't deploy the flow:  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/1/1/11653c434d491f066d7f47fe57e9ffeb0b2f1ffc.png)

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [1 July 2023 12:38 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520/7 "2023-07-01T12:38:11Z")

</div>

Your inject node is empty. Are you saying that it deploys ok if you have no inject node, but when you add an empty inject node not connected to anything, that it will not deploy?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [1 July 2023 12:42 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520/8 "2023-07-01T12:42:28Z")

</div>

Also tell us what hardware/os you are running on and how you installed node-red. Is this a home assistant install?

---

<div class="post-metadata">

**Author:** ![Kamiz](https://avatars.discourse-cdn.com/v4/letter/k/e274bd/32.png) [@Kamiz](https://discourse.nodered.org/u/Kamiz)\
**Post date:** [1 July 2023 17:35 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520/9 "2023-07-01T17:35:17Z")

</div>

It's not quite that. I can deploy an inject node without any problem as long as I don't have my SQL query in it, like in the json file i sent you  
But if I have my SQL query declared in it, I cannot deploy the flow, even if my inject node is not linked to my SQL node (or even if it is linked to nothing at all).  
If I delete my SQL node and delete its parameters, then I can deploy my inject node with my SQL query and deploy the entire flow.

Nodered is deployed in docker mode (on an Intel NUC). My entire HomeAssistant installation is installed on this same machine in docker mode.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [1 July 2023 19:24 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520/10 "2023-07-01T19:24:17Z")

</div>

The flow you posted has not got anything in the inject node

---

<div class="post-metadata">

**Author:** ![Kamiz](https://avatars.discourse-cdn.com/v4/letter/k/e274bd/32.png) [@Kamiz](https://discourse.nodered.org/u/Kamiz)\
**Post date:** [2 July 2023 07:58 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520/11 "2023-07-02T07:58:47Z")

</div>

Here is the flow with SQL query into inject node:

```auto
[
    {
        "id": "a46cf7a2ad40f4ad",
        "type": "tab",
        "label": "SQL",
        "disabled": false,
        "info": "",
        "env": []
    },
    {
        "id": "56ef87dcda28e55e",
        "type": "inject",
        "z": "a46cf7a2ad40f4ad",
        "name": "",
        "props": [
            {
                "p": "topic",
                "vt": "str"
            }
        ],
        "repeat": "",
        "crontab": "",
        "once": false,
        "onceDelay": 0.1,
        "topic": "SELECT table_schema \"homeassistant\", sum( data_length + index_length ) / 1024 / 1024 \"Data Base Size in MB\" FROM information_schema.TABLES GROUP BY table_schema;",
        "x": 610,
        "y": 80,
        "wires": [
            [
                "ee3e426232523c73"
            ]
        ]
    },
    {
        "id": "ee3e426232523c73",
        "type": "mysql",
        "z": "a46cf7a2ad40f4ad",
        "mydb": "bc82281c113049b7",
        "name": "",
        "x": 780,
        "y": 80,
        "wires": [
            [
                "78fb4048fd11c22b"
            ]
        ]
    },
    {
        "id": "78fb4048fd11c22b",
        "type": "debug",
        "z": "a46cf7a2ad40f4ad",
        "name": "debug",
        "active": true,
        "tosidebar": true,
        "console": false,
        "tostatus": false,
        "complete": "true",
        "targetType": "full",
        "statusVal": "",
        "statusType": "auto",
        "x": 950,
        "y": 80,
        "wires": []
    },
    {
        "id": "bc82281c113049b7",
        "type": "MySQLdatabase",
        "name": "",
        "host": "mariadb.local",
        "port": "3306",
        "db": "homeassistant",
        "tz": "",
        "charset": "UTF8",
        "credentials": {
            "password": "xxxxxxx"
        }
    }
]

```

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [2 July 2023 08:44 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520/12 "2023-07-02T08:44:55Z")

</div>

That deploys fine for me. I think this must be a Home Assistant issue, as that type of popup is not something I have ever seen. I don't use HA and very few here do.

Probably you should ask on a Home Assistant forum.

---

<div class="post-metadata">

**Author:** ![Kamiz](https://avatars.discourse-cdn.com/v4/letter/k/e274bd/32.png) [@Kamiz](https://discourse.nodered.org/u/Kamiz)\
**Post date:** [3 July 2023 19:14 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520/13 "2023-07-03T19:14:57Z")

</div>

I found the solution, it's my WAF (owasp/modsecurity) which blocked the flows.  
Thanks for your help

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [3 July 2023 19:45 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520/14 "2023-07-03T19:45:26Z")

</div>

Why only when you added the inject node?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [17 July 2023 19:46 UTC](https://discourse.nodered.org/t/unable-to-inject-sql-query/79520/15 "2023-07-17T19:46:25Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
