Remote-User header shall be trusted if comes from trusted frontend.
Attach a file by drag & drop or click to upload