Input validation for filenames/directories/renames should be handled at the server level and rejected if they contain illegal characters
This will stop rouge data from getting into the DB
Example: POST a rename request with a / in the filename
Server accepts but this breaks the webclient