Security Vulnerability Found in Heroku and Rails form_tag
benmanns.com
benmanns.com
You could use something like HMAC(form id:session id:secret) to validate forms, but then you run into problems with verification. The central issue is that tokens are generated in the view, but validated in the controller, so each controller would have to maintain a list of the forms that are authorized to POST to it.