Mass assignment
Mass assignment writes many model attributes from an array.
What it is
Mass assignment writes many model attributes from an array.
When to use it
Use validated input plus a narrow explicit allowlist.
Syntax
// Bad:
$user->update($request->all());
// Good:
$user->update($request->safe()->only(["name", "email"]));Example
class User extends Authenticatable
{
protected $fillable = ["name", "email"];
}
// Server-controlled changes:
$order->user_id = $request->user()->id;
$order->status = "pending";Common mistakes
validated() is only as safe as the validation rules; do not accept role, owner, or settled state from the client.