Protecting /upload

Hi,
Thanks for the reply, how do you attach a policy to the /upload route? I thought it might be the case to create a policy for it, but I could not work out in the files where in fact to put it.

To answer your question, it looks fine to me, try removing /api see if that works. On the version I’m using at least I POST too http://localhost:1337/upload
Thanks