Skip to content

Model Configuration

protectedProperties()

protectedProperties() — returns void

Available in: model Category: Miscellaneous Functions

Use this method to specify which properties cannot be set through mass assignment.

NameTypeRequiredDefaultDescription
propertiesstringno—Property name (or list of property names) that are not allowed to be altered through mass assignment.
// Without accessibleProperties() or protectedProperties(), mass assignment is open.
// set(massAssignmentStrict=true) fail-closes that case (opt-in; not the default).

// 1. Protect a comma-delimited list of properties from mass assignment in `models/User.cfc`.
// `firstName` and `lastName` cannot be changed via `updateAll()`, `new()`, `update()`, etc.
function config() {
	protectedProperties("firstName,lastName");
}

// 2. Using the named argument form to protect sensitive fields like `role` and `isAdmin`
function config() {
	protectedProperties(properties="role,isAdmin");
}