handling file uploads. change the filename after uploading (when you're storing it, using move_uploaded_file()) to the user's ID, or something else unique to that user.