Variable: CSV\_MIME\_TYPE
const CSV_MIME_TYPE: "text/csv; charset=utf-8" = "text/csv; charset=utf-8";Defined in: server/insights/export/csv.ts:39
Hand-rolled RFC 4180 CSV for a ReportResult. No dependency, no
streaming: an export is row-capped (see ExportService), so the whole
document fits in memory by construction.
RFC 4180 conformance:
- Records are separated by CRLF, including a trailing CRLF after the last record (the RFC makes it optional; emitting it keeps concatenation safe).
- A field is quoted iff it contains the delimiter, a double quote, CR, or LF.
- Embedded double quotes are escaped by doubling them.
- The UTF-8 BOM is prepended by default so Excel on Windows decodes non-ASCII
text correctly; set
bom: falsefor pipelines that treat it as data.
Formula (CSV-injection) guard
Excel/Sheets treat a cell starting with =, +, -, @, TAB, or CR as a
formula, which turns an exported customer-supplied string into code execution
(=cmd|' /C calc'!A0) or data exfiltration (=IMPORTXML(...)) on the
recipient's machine. This writer prefixes such a cell with a single quote
('), the conventional spreadsheet "treat as text" marker, and then quotes
the field.
The guard applies to text-typed cells and to headers — never to number
or money columns, whose values are produced by the SQL cast and must stay
machine-parseable (a negative amount legitimately starts with -). Disable
it with sanitizeFormulas: false only when the consumer downstream is not a
spreadsheet.