Question regarding docs / security: "This is not an issue with mass assignment."
I have a question regarding the security documentation page: https://filamentphp.com/docs/3.x/panels/resources/security
I understand the first part (all attributes are visible, but cannot be modified by malicious users). But what does "This is not an issue with mass assignment." mean in this context?
If attributes are mass assignable, they can be changed even if there are no form fields for them? (I am not a native speaker)
3 Replies
I would like to understand that sentence as well.
I think it just adds to the first one. Filament uses mass assignment per default and this might feel unsafe. But only values with a field will be updated at all.
Thank you @Dennis Koch for clarification.