---
url: https://scruple.dev/rules/security/no-untrusted-mass-assignment.md
description: Disallow wholesale persistence of request objects.
---

# security/no-untrusted-mass-assignment

Disallow wholesale persistence of request objects.

## What it checks

Project or validate an explicit field allowlist before request objects or spreads reach persistence and assignment sinks.

## Rule metadata

* Package: `@scruple/security`
* Category: Input validation
* Tags: mass-assignment, persistence, allowlist
* Default threshold: `0.9`
* Minimum confidence: `0.75`

## Examples

### Reported

```ts
await db.user.update({ where: { id }, data: req.body });
```

### Accepted

```ts
const { displayName } = ProfileSchema.parse(req.body); await db.user.update({ where: { id }, data: { displayName } });
```
