{"record":{"id":"70836770fb6174ed","repo":"laravel/framework","slug":"add-s-to-fillable-property-to-allow-mass-assign","errorCode":null,"errorMessage":"Add [%s] to fillable property to allow mass assignment on [%s].","messagePattern":"Add \\[(.+?)\\] to fillable property to allow mass assignment on \\[(.+?)\\]\\.","errorType":"exception","errorClass":"MassAssignmentException","httpStatus":null,"severity":"error","filePath":"src/Illuminate/Database/Eloquent/Model.php","lineNumber":693,"sourceCode":"     * @throws \\Illuminate\\Database\\Eloquent\\MassAssignmentException\n     */\n    public function fill(array $attributes)\n    {\n        $totallyGuarded = $this->totallyGuarded();\n\n        $fillable = $this->fillableFromArray($attributes);\n\n        foreach ($fillable as $key => $value) {\n            // The developers may choose to place some attributes in the \"fillable\" array\n            // which means only those attributes may be set through mass assignment to\n            // the model, and all others will just get ignored for security reasons.\n            if ($this->isFillable($key)) {\n                $this->setAttribute($key, $value);\n            } elseif ($totallyGuarded || static::preventsSilentlyDiscardingAttributes()) {\n                if (isset(static::$discardedAttributeViolationCallback)) {\n                    call_user_func(static::$discardedAttributeViolationCallback, $this, [$key]);\n                } else {\n                    throw new MassAssignmentException(sprintf(\n                        'Add [%s] to fillable property to allow mass assignment on [%s].',\n                        $key, get_class($this)\n                    ));\n                }\n            }\n        }\n\n        if (count($attributes) !== count($fillable) &&\n            static::preventsSilentlyDiscardingAttributes()) {\n            $keys = array_diff(array_keys($attributes), array_keys($fillable));\n\n            if (isset(static::$discardedAttributeViolationCallback)) {\n                call_user_func(static::$discardedAttributeViolationCallback, $this, $keys);\n            } else {\n                throw new MassAssignmentException(sprintf(\n                    'Add fillable property [%s] to allow mass assignment on [%s].',\n                    implode(', ', $keys),\n                    get_class($this)","sourceCodeStart":675,"sourceCodeEnd":711,"githubUrl":"https://github.com/laravel/framework/blob/e0f6eb3518ac29fbbca8529e97d0df7fc9f24481/src/Illuminate/Database/Eloquent/Model.php#L675-L711","documentation":"Thrown inside fill() when a single attribute key is not fillable AND the model is totally guarded ($guarded=['*']) OR Model::preventSilentlyDiscardingAttributes() is enabled. The check is per-key: the attribute was recognized in fillableFromArray (i.e. it is listed as fillable) but isFillable() still rejected it because the key is in $guarded, or it is not in $fillable at all under a guarded setup. This is the explicit per-attribute mass-assignment violation.","triggerScenarios":"Calling Model::create(['name' => $x]) (or fill/forceFill bypass) where the model has $fillable without 'name' and $guarded = ['*'] (totallyGuarded true), or where Model::preventSilentlyDiscardingAttributes() has been called and the key is being discarded.","commonSituations":"Adding a new column and forgetting to add it to $fillable; copying a fill array from a form request that includes a guarded field; turning on strict mode (Model::preventSilentlyDiscardingAttributes()) in tests or production to surface silent discards.","solutions":["Add the named key to the model's $fillable array.","If all fields are trusted, set protected $guarded = []; to disable guarding.","Set the attribute directly ($model->name = $x) or use forceFill(['name' => $x]).","If you only meant to update known fields, remove the stray key from the input array before fill."],"exampleFix":"// before\nclass User extends Model\n{\n    protected $fillable = ['name', 'email'];\n}\nUser::create(['name' => 'A', 'email' => 'b@c', 'role' => 'admin']); // throws\n\n// after - add 'role' explicitly when intended\nclass User extends Model\n{\n    protected $fillable = ['name', 'email', 'role'];\n}","handlingStrategy":"validation","validationCode":"// Only pass attributes the model actually allows\n$fillable = (new $modelClass)->getFillable();\n$safe = collect($input)->only($fillable)->all();\n$model->fill($safe);","typeGuard":"function isFillable(\\Illuminate\\Database\\Eloquent\\Model $model, string $key): bool {\n    return $model->isFillable($key);\n}","tryCatchPattern":"try {\n    $model->fill($input);\n} catch (\\Illuminate\\Database\\Eloquent\\MassAssignmentException $e) {\n    // log which key was rejected, surface to user, or use forceFill if intentional\n    report($e);\n}","preventionTips":["Keep $fillable in sync with migrations and form requests - add a column, update the array.","Use Model::preventSilentlyDiscardingAttributes() in non-production to catch missing fillable entries early.","In controllers, intersect request input with $model->getFillable() before fill().","Prefer explicit $fillable over $guarded=[] unless you fully trust all input."],"tags":["eloquent","mass-assignment","fillable","guarded","security"],"backgroundTag":null,"analyzedSha":"e0f6eb3518ac29fbbca8529e97d0df7fc9f24481","analyzedAt":"2026-08-11T20:52:37.562Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}