{% load static %} {% comment %} The host page, served by Django since port-plan step 9. It was `frontend/public/index.html`, served by shadow-cljs's `:dev-http`, and that key is gone. The bundle is unchanged: shadow-cljs writes it into `static/arthur/js` and staticfiles serves it from there, so `manage.py runserver` and `shadow-cljs watch app` are the whole dev loop with nothing copying files between them. The CSRF token is rendered so that Django sets its cookie, which is what `arthur.fx.http` reads to write the `X-CSRFToken` header. Saves are ordinary POSTs and PUTs with ordinary CSRF protection — no endpoint in this app is exempt. {% endcomment %}