{# The CSRF token as a hidden field, for forms that can submit with no JavaScript. htmx requests get it as a header instead, so a form that only ever submits via hx-post does not need this. Takes the token itself, not the whole context: {{ csrf_field(csrf_token) }}. #} {% macro csrf_field(token) %}{% endmacro %}