Protecting /upload

Ok, I’ll give that a go later, thanks!

Have you allowed public to use the upload route under users and permissions? If you have just allowed authorised users are sending a correct JWT token? Could also be an issue with moving into the extensions?