Blacklist your model fields for save()…

You’ve probably heard that in order to make your save() more secure, you can pass-in a third parameter of only

CakePHP and save() security

An interesting point came up on IRC… What happens if someone submits data to your application via a fake form?

15 Essential CakePHP Tips

Note, this article was written a long time ago for CakePHP version 1.x … many of the points described here

