What potential pitfalls should be considered when implementing file uploads in PHP, especially in terms of file type validation?

When implementing file uploads in PHP, one potential pitfall to consider is the risk of allowing users to upload malicious files disguised as harmless file types. To mitigate this risk, it's crucial to implement proper file type validation to ensure that only safe file types are accepted for upload. This can be done by checking the file's MIME type or extension against a whitelist of allowed file types.

// Example code snippet for file type validation in PHP file upload

$allowedFileTypes = ['image/jpeg', 'image/png', 'image/gif'];

if (isset($_FILES['file'])) {
    $fileType = mime_content_type($_FILES['file']['tmp_name']);
    
    if (!in_array($fileType, $allowedFileTypes)) {
        echo "Invalid file type. Only JPEG, PNG, and GIF files are allowed.";
    } else {
        // Process the file upload
    }
}