What are the best practices for checking file extensions in PHP file uploads?

When allowing file uploads in PHP, it is important to validate the file extensions to prevent malicious files from being uploaded to the server. One common approach is to check the file extension against a list of allowed extensions. This can be done using the pathinfo() function to extract the file extension and then comparing it against an array of allowed extensions.

$allowedExtensions = array('jpg', 'jpeg', 'png', 'gif');
$uploadedFile = $_FILES['file']['name'];
$fileExtension = pathinfo($uploadedFile, PATHINFO_EXTENSION);

if (!in_array($fileExtension, $allowedExtensions)) {
    // File extension is not allowed
    // Handle the error or reject the file upload
} else {
    // File extension is allowed
    // Proceed with file upload
}