the create endpoint read OwnerID off the request body — stamping it from the session instead, and why a field you validate is still a field you trusted