I have implemented a Backend for Frontend for my single page application, such that XSS attacks are not able to retrieve the JWTs. This approach uses a backend that stores the jwts in an http-only cookie, hence CSRF attacks are now possible. To prevent those as well, I have read that creating random tokens should prevent that.
So I was wondering if the following approach is sufficient or not: A dedicated API that creates and stores CSRF tokens as Guids in a temporary store. This API is used to retrieve a new token and the backend then can check if the token exists in the temporary store.
Any recommendations are welcome!