Always pass $request->validated() or $request->safe() into model creation methods to prevent mass-assignment vulnerabilities.
Passing $request->all() directly into Model::create() exposes applications to mass assignment vulnerabilities if unfillable or un-sanitized fields are submitted in HTTP request payloads.
use App\Http\Requests\StoreUserRequest;
use App\Models\User;
public function store(StoreUserRequest $request)
{
// ❌ UNSAFE: Passes raw request keys including hidden payload injection
// User::create($request->all());
// ✅ SAFE: Passes only explicitly validated fields
$user = User::create($request->validated());
}
- validated() filters HTTP input down to explicitly defined validation rules
- Prevents malicious form input keys from modifying un-fillable model attributes
- Pair with FormRequest classes for clean controller separation
Related Tips
View all tips →Avoid Duplicating Authorization Logic with Gate::define() and Gate::authorize()
Centralize authorization checks in Gate::define() and call Gate::authorize() in controllers instead of repeating manual if checks.
Prevent Information Disclosure with Gate::denyAsNotFound()
Use Response::denyAsNotFound() in policies to return a 404 Not Found response instead of 403 Forbidden, concealing the existence of private resources.