Hi
I have created a new form (using xml view) for Odoo Website, and added a file field there.
I was sure that Odoo has built-in malicious file check mechanism, but it looks like I can upload everything there, including .js and .php file with bad code.
What is the right mechanism to secure such forms?