protect_from_forgery(options = {})
Instance Public methods
Turn on request forgery protection. Bear in mind that only non-GET,
HTML/JavaScript requests are checked.
class ApplicationController < ActionController::Base
protect_from_forgery
end
class FooController < ApplicationController
protect_from_forgery except: :index
You can disable CSRF protection on controller by skipping the verification
before_action:
skip_before_action :verify_authenticity_token
Valid Options: