Don't allow user_id to be provided as a parameter, using strong params.
So, you could create the relation like that:
@friendship = current_user.friendships.new(contact_id: other_user.id)
Also make sure you provide the correct condition for current_user.
That's it... user_id is implied but never provided.