Reported by @yshmarov Currently, the resource generated via generator for oauth callback skips the authenticity token. Explore `omniauth-rails_csrf_protection` gem