The threat is that the user can easily go to this URL and perform a potentially destructive action.
/noform/edit
/noform/update
Normal view scans GETfor server requests . It is assumed that any page that you can easily go to (or enter in the address bar) will not perform any functions that modify the data.
A POST , AJAX, , .
, "" PUT DELETE , .
, update edit - :
button_to "Add new tracker", noform_path, :method => :put
- , , , - . , , update .