Correct, the technical term for it is 'XSSI', or Cross Site Script Inclusion.
Apologies if the title made it seem like not using javascript arrays was a magic bullet to preventing all CSRF.
Regardless, it seems CSRF is much more widely known than XSSI, so you could say worrying about the distinction is just pedantry. I was very surprised when I searched earlier and could not so much as find an OWASP mention of XSSI. Still very important to know though.