File Uploads Are Attack Surfaces
Allowing uploads introduces real risk.
So I enforced strict controls:
- blocked executable and unsafe file types
- constrained file sizes
- ensured only expected formats are accepted
No “trust the user” shortcuts.
Validation Is Not Just UI Feedback
Most forms validate for UX.
This one validates for security.
Every input is treated as untrusted:
- sanitized before submission
- structured to avoid injection risks
- aligned with backend expectations
Keeping It Simple (On Purpose)
Security-heavy forms often become intimidating.
I kept the interface minimal and direct, so users can focus on reporting — not figuring out how to use the form.