security mechanisms (against path traversal) is in place

we access files from local storage, not sure if this can be leveraged to access files outside of the storage directory.

also json/javascript injections should be checked