Three share_tests were failing in CI:
1. public_key_lookup_returns_recipient_identity_key — passed the email
as a JSON body on a GET, but send_json builds the URI verbatim and
ignores the body for GET. The query string was never formed, so the
handler got an empty email. Fix: put ?email=... in the URI directly
(URL-encoding the '@').
2. public_key_lookup_404s_for_unknown_or_keyless_user — same root cause.
3. owner_shares_recipient_reads_owner_revokes — asserted the recipient's
write would return 201 or 403, but create_medication returns 200 OK
(Axum's default for Ok(Json(...))), and the write currently succeeds
because the create handler doesn't check ownership (issue #12). The
write is attributed to the recipient, not the owner, so the owner's
data is still untouched — which is what the test really wants to
prove. Accept 200 (current) or 403 (once #12 lands); documented the
tie to #12.