7d7e524756
Resolve a client-supplied workspace dir safely: canonicalize via toRealPath, reject privileged locations, clamp to [tools] allowed_workspace_roots (permissive when unset, logged), fall back to the boot default on any rejection. PathJail made non-internal so the server can reuse its symlink-safe containment. (Axis 2 Phase A, task 4.)