{% load static %} {% comment %} The host page, served by Django since port-plan step 9. It carries no styles of its own any more. They are `static/arthur/app.css`, which staticfiles serves from the same tree as the bundle — the page grew a five-pane application chrome and "the styles" stopped being a thing you read in passing on the way to the markup. The bundle is unchanged: shadow-cljs writes it into `static/arthur/js` and staticfiles serves it from there, so `manage.py runserver` and `shadow-cljs watch app` are the whole dev loop with nothing copying files between them. The CSRF token is rendered so that Django sets its cookie, which is what `arthur.fx.http` reads to write the `X-CSRFToken` header. Saves are ordinary POSTs and PUTs with ordinary CSRF protection — no endpoint in this app is exempt. {% endcomment %}