Public API endpoints doesn't need to have CSRF protection
Attach a file by drag & drop or click to upload