feat: disable csrf for RQLIO controllers

As of Cubicweb 3.32, there is a CSRF check on every controllers. However, the
RQLIO one is a bit peculiar, as it is intended to be used by authenticated
3rd-parties, meaning that we can disable CSRF check because the RQLIO
controllers does not rely on cookie authentication.
......@@ -114,6 +114,7 @@ class RqlIOController(Controller):
'application/json', 'multipart/form-data', mode='any') &
require_csrf = False
def json(self):
contenttype = self._cw.get_header('Content-Type', raw=False)
