Understanding & Mitigating Cross-Site Request Forgery (CSRF)