The UI that warns about a CSRF should allow users (maybe only advanced ones?) to see the requests that leads to this warning. Example of mock ups from Thiago Krieck:
This message was sent by Atlassian Jira (v9.3.0#930000-sha1:287aeb6)
If image attachments aren't displayed, see this article.