Controller
authenticityToken()
Signature
Section titled “Signature”authenticityToken() — returns string
Available in: controller
Category: Miscellaneous Functions
Description
Section titled “Description”Returns the raw CSRF authenticity token
Examples
Section titled “Examples”// 1. Embed the CSRF token in a manually-built form hidden field
token = authenticityToken();
writeOutput('<input type="hidden" name="authenticityToken" value="' & token & '">');
// 2. Pass the token as a request header for an AJAX call (e.g. in a JavaScript data island)
writeOutput('<meta name="csrf-token" content="' & authenticityToken() & '">');
// JavaScript can then read this and send it as the X-CSRF-Token header with each POST request.
// 3. Include the token in a JSON API response body so a client can replay it
tokenValue = authenticityToken();
writeOutput(serializeJSON({authenticityToken = tokenValue}));