I can no longer reproduce the exact issue previously reported which was related to a delay in the CSRF token being available to our JS.
This, theoretically, would more likely be related to the page load getting an old version of the token. There is code to prevent this though.