Introduce a 'secure' filesystem disk to prevent public access to sensitive
commitment form uploads. Files are now stored in a non-public directory
and served via a protected controller method that validates user ownership.
Additionally, implement shipment authorization policies to ensure users
can only access PDF documents (AWB, invoice, labels) belonging to their
own orders.
Other changes:
- Add production environment check for Zarinpal gateway configuration
to prevent accidental use of sandbox credentials.
- Move discount code and commitment form routes under authentication
middleware for improved security.
- Add `ShipmentPolicy` to handle resource authorization.