Endpoints can access anything on server local filesystem

Endpoints that take an absolute path e.g. '/paths/watch_input' are technically a vulnerability; best to limit this to a top-level data directory