file-upload-handling.txt
Users need to upload <what kind of file>, up to <size>.

Implement it with these checks spelled out:
- Size limit enforced on the server, not just the form.
- Type checked by actual content, not by the filename extension.
- Stored with a name I generate, never the name the user sent.
- Stored somewhere it cannot be executed or served as HTML.

Tell me what an attacker would try here and which check stops it.

An upload form is a stranger writing files onto your server. Every one of those rules exists because someone skipped it.