* feat: use base58-encoded root in file API paths, remove symlink check
- Replace query param `?root=` with path param `/:root/` using base58 encoding (bs58)
- Remove `verifyRealPath` symlink check — worktrees legitimately reside outside project root
- Support symlinks in directory listings via stat() resolution
- Frontend encodes root path with inline base58 implementation
* fix: restore realpath guard for write operations (save/delete)
Read operations (show/raw) remain unrestricted for worktree access.
Write operations (save/delete) keep symlink traversal protection.
* refactor: remove verifyRealPath entirely, root path is the boundary