ac42a6d3cc
│ Steps 1-6 │ Setup: admin's resources + create bob + bob's home folder │ │ Step 7 │ REST: bob can't create a folder inside admin's home → 404 │ │ Step 8 │ REST: bob can't create inside admin's private folder → 404 │ │ Step 9 │ REST: parent_id: null auto-resolves to bob's home (documents the convenience) │ │ Step 10 │ REST: positive control — bob creates in his own home → 201 │ │ Step 12 │ REST: bob can't move his file into admin's folder → 404 │ │ Step 13 │ REST: bob moves file to root (null) → 200 (legitimate root state) │ │ Step 14 │ REST: bob can't read admin's file → 404 │ │ Step 15 │ REST: admin's tree integrity preserved │ │ Step 16 │ WebDAV: path-prefix isolation rewrites cross-user paths into caller's tree │ │ Step 17 │ WebDAV: positive control MKCOL in bob's own tree → 201 │ │ Step 18 │ WebDAV: bob's home contains the rewritten "My Folder - admin" sub-folder, proving the isolation rerouted the attack │ │ Step 19 │ WebDAV: admin's tree never sees bob's WebDAV traffic │