test(api): prove header-injection sanitizer via staged.file_name path (#15-4)
Code review found the download-header injection test only fed the malicious CRLF/quote payload into the ignored request.fileName field, never into the DB-sourced staged.file_name that _content_disposition actually sanitizes - so the assertion passed even against a no-op sanitizer. Add a direct unit test for _content_disposition and a router test with a malicious staged.file_name, and reword the original assertion to state what it actually proves (request fileName is ignored, not that it's sanitized).