I think this is a great example of all the small details we take for granted in the tools we use, and we would miss without realising when following these tips.
That hidden CSRF field can be added without form_with though, and Rails still protects against not including it. I left it out of the example as it didn't seem relevant