3 ms·
That hidden CSRF field can be added without form_with though, and Rails still protects against not including it. I left it out of the example as it didn't seem
by tonyennis 3y ago
That hidden CSRF field can be added without form_with though, and Rails still protects against not including it. I left it out of the example as it didn't seem relevant
- stanislavb 3y agoYes, it can be added, but manually going over all form. Also, how would it protect against a CSRF without the token in place? Note: I totally agree that we should strive to go HTML first. However, this specific example is a bit unfair.