SonarQube flagged three hotspots in the admin router: multer was configured with no content length limits, and stored filenames were derived from Date.now() plus Math.random(). - Cap the multipart body on every dimension: 6 files, 8 MiB per image, 8 fields, 64 KiB per field. Without limits a single request could fill the uploads volume. - Generate stored filenames with crypto.randomUUID() so paths are not predictable. Image ordering is unaffected; sort_order already drives it. - Wrap the upload middleware to translate MulterError into 413/400 JSON. The app mounts no error handler, so a limit rejection would otherwise surface as an HTML 500. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>