The bucket should never be publicly writable. The "go-to" techniques are signed POST requests [1] and signed URLs [2].
[1] https://docs.aws.amazon.com/AmazonS3/latest/API/sigv4-post-e...
[2] https://docs.aws.amazon.com/AmazonS3/latest/dev/PresignedUrl...