Skip to content
← All rules
SecurityInput validation

security/no-untrusted-mass-assignment

Project or validate an explicit field allowlist before request objects or spreads reach persistence and assignment sinks.

mass-assignmentpersistenceallowlist
TypeScript
await db.user.update({ where: { id }, data: req.body });
Finding

Disallow wholesale persistence of request objects.

Setup

Install the package, register its plugin factory, then enable the rule.

Install the package

pnpm add -D @scruple/security

Register the plugin

In scruple.config.ts, register the factory under the security namespace used by the rule ID.

import { security } from "@scruple/security";

plugins: {
  "security": security(),
},

Enable the rule

"security/no-untrusted-mass-assignment": "warn"
Package
@scruple/security
Default threshold
0.9
Minimum confidence
0.75

Released under the MIT License.