cubicweb-container #3547361 permissions on 'border-crossing' composite relation are not correctly set

Consider a border crossing relation composite in an entity type not in container scope. The current implementation of rdefs_roles_to_container (in setup_container_rtypes_security) will find that the so-called "role to container" is the composite, which is not in the scope of the container. So the resulting rql expression will never apply.

It seems to me that considering the compositiness here is a bit arbitrary, and it does not work in this case.

done in2.4.0
patchConfig: provide the `.setup_rdefs_security` helper
Fix role to container determination for border-crossing relation permissions setup