Add locked user fixture (user18, status=3) and test that both disabled and locked users are rejected across all auth paths: API tokens, CalDAV basic auth, CheckUserCredentials. Ref: GHSA-94xm-jj8x-3cr4