I'll abbreviate how it works:
The /download/ folder contains the ACTUAL original files.
The /pub/ folder contains dynamically-created symlinks TO those original files.
The CUSTOMER is given the temporary symlink for their download, so that they cannot share it with their friends and steal your files.
A properly-configured server will very naturally follow the symlink to find the correct file to serve to the customer, TRANSPARENT to the customer.
So, when your store is configured to use Download-by-redirect, these symlinks are how it works.
If you turn off Download-by-redirect, THEN your customers will be given direct links to your files in your /download/ folder. If that's what you want, or if your host is unable to make symlinks work properly, then turn that switch off.
The /download/.htaccess IS NEVER USED AT ALL if you're using the symlink approach. So that's completely irrelevant here.
The /pub/.htaccess contains a statement to tell the server to follow symlinks. If your host isn't capable of configuring the server to allow the use of such directives in .htaccess, then find a host who knows what they're doing, or at least someone AT your hosting company who knows the bigger technical picture of how the servers work and how they're configured.
The rest of the entries in the .htaccess files are intentionally there to prevent customers from accessing files they're not allowed to access. By default it ALLOWS several file extensions, including the .zip that you're using in your case. So, again, the .htaccess should not be interfering here ... unless the server is improperly configured.
You could TEMPORARILY rename your /pub/.htaccess to htaccess_OFF so that it's disabled and DOES NOTHING TO PROTECT YOU. It also will probably still break since renaming it also removes the follow-symlinks directive. So, while the "forbidden" may disappear, it'll probably turn into a "not found" response, and then you're still no further ahead.