Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
When the HTML backend renders pages in a headless browser (HTMLBackendOptions(render_page=True)), the enable_local_fetch option is not enforced. A crafted HTML file can embed an arbitrary local file (for example with <iframe src="file:///…">), and that file's contents appear in the page image attached to the returned DoclingDocument.