NetBox sets CSRF_COOKIE_HTTPONLY = True, so document.cookie can never
see the csrftoken cookie - elevation.js's reorder POST always sent an
empty X-CSRFToken header, Django's CSRF middleware rejected every
request with 403 before it reached the view, and the JS's failure
path (removeAttribute('transform') + a small status message) made a
dragged device silently snap back to its old position on every single
attempt, not just occasionally.
Render {% csrf_token %} on the concept detail page and read the token
from that hidden input instead of the cookie - the standard approach
for a plain fetch() POST outside of a form.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>