Use whitelist (:only => [..]) when skipping CSRF check near line 3: skip_before_filter(:verify_authenticity_token, :except => :index) > source: Brakeman Report - 20/08/2014