Restrict Todo API mark_as_done endpoint to the user's todos only
Attach a file by drag & drop or click to upload