Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

Form authenticity token in form tag should be set to display:inline

#2846

When a form is rendered using form_tag or form_for, the form authenticity token is of course placed right after the <form> tag automatically. While this is a hidden field so it won't show up, it is wrapped in a div tag that does not have display: inline set on it. This means that if you want your form to be inline, you have to set something like

form div { display: inline }

or else the form will have a line break where the form authenticity token hidden field is. However, because there's no way to target this exactly, if you happen to have any other divs in your form for whatever reason, you'll have to give those classes or something so you can override the display: inline in your CSS.

I don't actually know why the hidden field is wrapped in a div, maybe there's some reason, but I've made a patch that sets this div to display: inline.

Reported by Elliot Winkler · June 28th, 2009 @ 08:29 AM

State: resolved
Milestone: 2.x
Assigned to: nobody
Importance: none

Activity

  1. Repository
    Repository
    • State changed from new to resolved

    (from [0d3c5f0a822cd1b6029b5f619774b7794a94f370]) Patch FormTagHelper so that when a form tag is created, the div which holds the form authenticity token is set to display:inline [#2846 state:resolved]

    Signed-off-by: Yehuda Katz + Carl Lerche ykatz+clerche@engineyard.com
    http://github.com/rails/rails/commit/0d3c5f0a822cd1b6029b5f619774b7...

    July 2nd, 2009 @ 01:14 AM

  2. Repository
    Repository

    (from [8bb510f6c1e235f5fb1cf9e79af759a429a497b0]) Patch FormTagHelper so that when a form tag is created, the div which holds the form authenticity token is set to display:inline [#2846 state:resolved]

    Signed-off-by: Yehuda Katz + Carl Lerche ykatz+clerche@engineyard.com
    http://github.com/rails/rails/commit/8bb510f6c1e235f5fb1cf9e79af759...

    July 2nd, 2009 @ 01:14 AM

  3. Jeff Talbot
    Jeff Talbot

    This is marked resolved, but we recently had an issue with the patch: the inline style of "display:inline" in the HTML cannot be overridden by a stylesheet and is creating issues for us in Safari. It seems incorrect for Rails to be injecting a block level element inside a form just to hold a hidden input, but if for some reason this is absolutely necessary, it seems it would be preferable to set the style to "display:none".

    Anyone agree that a better solution should be implemented? If so, I wouldn't mind creating a new patch.

    August 25th, 2009 @ 01:20 PM

  4. Elliot Winkler
    Elliot Winkler

    Now that I think about it some more, that makes more sense. At first I was concerned that hiding the hidden fields using CSS would cause the token to not be submitted along with the form, but I just tested setting the div to "display: none" like you just said, and I didn't get an InvalidAuthenticityToken error or anything like that, so obviously it still works. So that sounds good to me.

    August 26th, 2009 @ 02:40 AM

  5. Elliot Winkler
    Elliot Winkler

    As to being able to override it using a stylesheet, I can't see a use case for it, but looks like you have one?

    August 26th, 2009 @ 02:42 AM

  6. Jeff Talbot
    Jeff Talbot

    Cool. Regarding the CSS overriding--was just mentioning that it wouldn't work for setting it to display:none since it had the inline style set on the tag (which takes precedence over anything else).

    August 26th, 2009 @ 09:34 PM