The delete_archive() function in backend/app/services/archive.py now has these safety checks:
1. Empty path check: Refuses to delete files if file_path is empty/whitespace
2. Path containment check: Verifies archive_dir is inside settings.archive_dir
3. Depth check: Ensures we're at least 1 level deep inside archive directory
4. Logging: All security refusals are logged with SECURITY prefix
5. Database record still deleted: Even if file deletion is refused, the orphan DB record is cleaned up
Before the fix:
file_path = settings.base_dir / archive.file_path # If empty: /opt/bambuddy
archive_dir = file_path.parent # = /opt
shutil.rmtree(archive_dir) # DELETES /opt!