* blacklist all fields by default
* don't use blacklist in get_authorized_fields which is called to see if
a field can be added to a form, instead only use it afterwards to see
if the field can be written to by the formbuilder. That way
formbuilder can whitelist fields which are actually added to forms
on-demand resulting in a more secure interaction
In noupdate, the opt-in setting is ignored by migrations and breaks the
corresponding feature. If the feature is undesirable, don't install the
module.