Looks nice, you need to make it so the file is force downloaded. I uploaded an html file and it just viewed it.
But be careful! If you serve user-uploaded, untrusted files from the same domain as everything else, that's a great way to make yourself vulnerable to XSS.