feat: requires the NO-CSRF-CHECK header to bypass CSRF check

BREAKING CHANGE: the NO-CSRF-CHECK is not required
