Skip to content

View Helpers

authenticityTokenField()

authenticityTokenField() — returns string

Available in: controller Category: General Form Functions

Returns a hidden form field containing a new authenticity token.

// 1. Include CSRF token in a plain HTML form that POSTs data
//    (use this when you are not using startFormTag())
<form action="#urlFor(route='posts')#" method="post">
  #authenticityTokenField()#
  <!--- other fields here --->
</form>

// 2. Not needed for GET forms — GET requests are not CSRF-protected
<form action="#urlFor(route='posts')#" method="get">
  <!--- no token required --->
</form>