From cd8d341971374ac35a702e7d542e17385eb8a999 Mon Sep 17 00:00:00 2001 From: eYinka Date: Thu, 10 Sep 2026 15:23:30 +0100 Subject: [PATCH] Force an Asset Manager handshake on the draft stack Each draft image on a page independently triggers its own Signon/Asset Manager OAuth handshake when there's no existing session. With more than one draft image, these handshakes race and clobber each other's CSRF state, so all but (at best) one image fail to load. In this commit, we load a single placeholder image from the draft-assets host, and once its request has settled - whether it succeeds or fails, we only care that the handshake has finished; we then retry every draft image already on the page. Added an `asset-manager-session.js` script that is inlined directly into the layout files via a `