Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In Rails, redirect_to sends a redirect response—HTTP 302 by default—that tells the browser to make a new request to another URL. It does not jump to another controller action, and it does not stop the current Ruby action from running. Use an explicit return when execution must end.

What redirect_to does

A redirect and a render produce different responses. Rendering returns a response body for the current request; redirecting tells the browser to request a different URL. The Rails Guides describe redirect_to as telling the browser to send a new request for a different URL: Layouts and Rendering in Rails.

For example, redirect_to photos_url asks the browser to visit the photos URL. The browser’s follow-up request is separate from the request that ran the current action.

Does redirect_to stop the action?

No. Ruby continues executing the action after redirect_to unless you return or otherwise halt control flow. A redirect response may already be set, but later statements can still run and cause unintended work or errors.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
def create
  if @record.save
    redirect_to @record
    return
  end

  render :new, status: :unprocessable_entity
end

The explicit return makes the successful branch exit before reaching the render. Choose control flow deliberately rather than treating a redirect like a server-side jump.

Choose a redirect status for the request

The documented default is HTTP 302, a temporary redirect. Pass status: when the response should use another status. Rails Guides show 301 as an example; the Rails 8.1 Action Controller guide uses 303 (:see_other) when redirecting after logout. These statuses have different HTTP semantics, so select one to match the behavior you intend rather than making every redirect permanent. See Layouts and Rendering in Rails and the Rails 8.1 Action Controller Overview.

redirect_to photos_url, status: :see_other

Redirect to the previous page with a fallback

Use redirect_back(fallback_location: ...) when the destination should be the page the request came from. Rails gets that location from the HTTP_REFERER header, which may be absent, so always supply a fallback.

redirect_back(fallback_location: root_path)

If the request has no usable referrer, Rails can redirect to root_path instead of relying on a header browsers do not guarantee to send. The API is documented in Layouts and Rendering in Rails.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Pass a flash message to the destination

A redirect can carry a flash value such as notice, alert, or a custom key. The value is available on the subsequent request; Rails does not display it automatically. The destination action or view must decide whether and how to show it.

redirect_to photos_url, notice: "Photo was created."

If the destination redirects again and the message must survive that additional request, use flash.keep as appropriate. See the Rails 8.1 Action Controller Overview.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Protect redirects to external or relative destinations

Redirect safety depends on the application’s Rails configuration. Rails documents config.action_controller.action_on_open_redirect for handling redirects to external hosts, with behaviors including :log, :notify, and :raise. The application can also specify trusted hosts with config.action_controller.allowed_redirect_hosts.

Rails also documents config.action_controller.action_on_path_relative_redirect for path-relative redirect handling, with logging, notification, and exception behaviors. Defaults for these settings depend on the version selected by config.load_defaults; check the effective configuration for the application rather than assuming one default applies to every Rails app. The configuration guide notes that the newer action_on_open_redirect setting replaces the deprecated raise_on_open_redirects option. Details are in Configuring Rails Applications.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When a destination comes from request parameters, do not trust it merely because Rails provides redirect protections. Validate that the destination matches the hosts and paths your application intends to allow, and keep the app’s redirect settings aligned with that policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.