This is on the server side, on the app. If your supposedly-safe methods aren't safe, then CSRF may not be your biggest problem.