Pablo Bello said almost 7 years ago on WYSIWYG Editor with Trix :

To add CSRF:

xhr.setRequestHeader('X-CSRF-Token', $('meta[name="csrf-token"]').attr('content'));
xhr.setRequestHeader 'X-CSRF-Token', $('meta[name="csrf-token"]').attr('content')