Extend assertSafeApiId to organizations, resource-control, permissions, tokens, and update paths; harden org UI XSS and attachment confinement.
Add goApiPath guard on betterdeskApi axios requests, sanitize org/device IDs in policy routes, and confine server-management directory listings with resolveChildPath.