Progress
I realized that I forgot to make the bindings updatable and hidden. That answers question 1, but but has raised a new issue.
The following shows up in my browser in place of the "add to cart" button:
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '' at line 1