CSRF is defeated in layers, not spells. CSRF Methods Guide explains the eight standard defenses — tokens, cookies, headers, policies and signatures — with effort, effectiveness and step-by-step setup for each.
Then run the self-assessment: tick what you already do, and the guides list the missing layers.