Deny cookie auth for GraphQL CI linting

What does this MR do and why?

We intend for the linting feature to only be accessible with an API token.

Merge request reports

Loading