Methods
Instance Public methods
Alias for csrf_meta_tags
Returns meta tags “csrf-param” and “csrf-token” with the name of the cross-site request forgery protection parameter and token, respectively.
<head> <%= csrf_meta_tags %> </head>
These are used to generate the dynamic forms that implement non-remote links with :method.
Note that regular forms generate hidden fields, and that Ajax calls are whitelisted, so they do not use these tags.
This method is also aliased as
csrf_meta_tag
# File actionpack/lib/action_view/helpers/csrf_helper.rb, line 19 19: def csrf_meta_tags 20: if protect_against_forgery? 21: [ 22: tag('meta', :name => 'csrf-param', :content => request_forgery_protection_token), 23: tag('meta', :name => 'csrf-token', :content => form_authenticity_token) 24: ].join("\n").html_safe 25: end 26: end