https://oscarjiang.site/posts/secret-of-rails-csrf-token.html/
Rails CSRF token 探秘 - 姜鹏的博客