A file read or stream is opened using a path derived directly from HTTP request input.
Canonicalize and validate the path against an allowlisted base directory before opening the file.