I'm working on a React app and am thinking about implementing a CSRF mitigation technique. I decided to go with Same-Site cookies but before that, I was looking into using CSRF tokens and read numerous posts saying they should be stored in a hidden form field. What I'd like to know is if there is a difference between storing it in a hidden field and storing it in something like a class variable? If the point of it is to keep somewhere for when you a ready to send a request to the server, does it matter how it's stored on the client-side?