Understanding the Rails Authenticity Token

前端 未结 10 1284
攒了一身酷
攒了一身酷 2020-11-22 05:55

I am running into some issues regarding the Authenticity Token in Rails, as I have many times now.

But I really don\'t want to just solve this problem and go on. I w

10条回答
  •  予麋鹿
    予麋鹿 (楼主)
    2020-11-22 06:32

    The authenticity token is designed so that you know your form is being submitted from your website. It is generated from the machine on which it runs with a unique identifier that only your machine can know, thus helping prevent cross-site request forgery attacks.

    If you are simply having difficulty with rails denying your AJAX script access, you can use

    <%= form_authenticity_token %>
    

    to generate the correct token when you are creating your form.

    You can read more about it in the documentation.

提交回复
热议问题