#15-4 배경지식 다운로드 IDOR 차단 + scratch 스트리밍
Code review found the download-header injection test only fed the malicious CRLF/quote payload into the ignored request.fileName field, never into the DB-sourced staged.file_name that _content_disposition actually sanitizes - so the assertion passed even against a no-op sanitizer. Add a direct unit test for _content_disposition and a router test with a malicious staged.file_name, and reword the original assertion to state what it actually proves (request fileName is ignored, not that it's sanitized).