Ruby on Rails 8.0.0.1 Module ActionController::RequestForgeryProtection::ClassMethods actionpack/lib/action_controller/metal/request_forgery_protection.rb Turn on request forgery protection. Bear in mind that GET and HEAD requests are not checked. class ApplicationController < ActionController::Base protect_from_forgery end class FooController < ApplicationController protect_from_forgery except: :