[Rails5] Force the `protect_from_forgery` callback run first
What does this MR do?
Since Rails 5.0 the protect_from_forgery callback doesn't run first by
default anymore.
Instead it gets inserted into callbacks chain where callbacks get called in order.
This MR forces the callback to run first.
Are there points in the code the reviewer needs to double check?
No.
Why was this MR needed?
Screenshots (if relevant)
No.
Does this MR meet the acceptance criteria?
- 
Changelog entry added, if necessary 
- 
Documentation created/updated 
- 
API support added 
- 
Tests added for this feature/bug 
- Conform by the code review guidelines
- 
Has been reviewed by a UX Designer 
- 
Has been reviewed by a Frontend maintainer 
- 
Has been reviewed by a Backend maintainer 
- 
Has been reviewed by a Database specialist 
 
- 
- 
Conform by the merge request performance guides 
- 
Conform by the style guides 
- 
If you have multiple commits, please combine them into a few logically organized commits by squashing them 
- 
Internationalization required/considered 
- 
End-to-end tests pass ( package-and-qamanual pipeline job)
What are the relevant issue numbers?
Closes #48204 (closed)
Edited  by blackst0ne