PageSourceSearch

https://softwarecrafts.uk/_next/static/chunks/pages/100-words/day-12-26491c43722e675e.js

js softwarecrafts.uk collected 2026-10-01 14:03:30 UTC 2,294 bytes, 1 lines download raw bytes

1(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[9949],{39266:function(e,t,n){(window.__NEXT_P=window.__NEXT_P||[]).push(["/100-words/day-12",function(){return n(12425)}])},12425:function(e,t,n){"use strict";n.r(t),n.d(t,{meta:function(){return i}});var s=n(85893),o=n(11151),a=n(53841);let i={author:"Andrew Miller",date:"2024-01-23",title:"Don't use `__all__`",description:"A best practice with Django Forms",tags:["100 words","django","forms","tips"]},MDXLayout=e=>(0,s.jsx)(a.B,Object.assign({meta:i},e));function _createMdxContent(e){let t=Object.assign({p:"p",code:"code"},(0,o.ah)(),e.components);return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsxs)(t.p,{children:["One thing I often see Django developers do when creating Django forms or Django Rest Framework Serializers is to use the ",(0,s.jsx)(t.code,{children:"__all__"})," shortcut to specify all fields from the Model.\nPersonally I would remove this as an option as it encourages 2 bad practices IMO."]}),"\n",(0,s.jsxs)(t.p,{children:["Firstly this introduces a security risk of leaking information later in the codebase's life. When at a later date a new model field is added, but doesn't want to be exposed to this form then ",(0,s.jsx)(t.code,{children:"__all__"})," leads to this happening more easily.\nIt is the same reasoning as to why ",(0,s.jsx)(t.code,{children:"exclude"})," shouldn't be used on Forms or Serializers."]}),"\n",(0,s.jsxs)(t.p,{children:["Secondly, you might think it's a handy shortcut since you are just repeating information. However the list of fields in a Form represent a fundamentally different concept in your app. Model fields declare how data should be stored\nin your database, a Form doesn't represent this, but what data a user ought to be inputing into a webpage. These are related but not the same. A quick example of this is agreeing to T&C's, in the database it is often best to store this\nas a DateTimeField, where as Form would simply require a checkbox. The same would go for fields that get populated on model ",(0,s.jsx)(t.code,{children:"save"})," etc."]})]})}t.default=function(e={}){return(0,s.jsx)(MDXLayout,Object.assign({},e,{children:(0,s.jsx)(_createMdxContent,e)}))}}},function(e){e.O(0,[407,8819,4825,9774,2888,179],function(){return e(e.s=39266)}),_N_E=e.O()}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.