Kaizen
Browse modulesInsightsinsights/serverSchemas and constants

Variable: CSV\_MIME\_TYPE

const CSV_MIME_TYPE: "text/csv; charset=utf-8" = "text/csv; charset=utf-8";

Defined in: server/insights/export/csv.ts:39

Hand-rolled RFC 4180 CSV for a ReportResult. No dependency, no streaming: an export is row-capped (see ExportService), so the whole document fits in memory by construction.

RFC 4180 conformance:

  • Records are separated by CRLF, including a trailing CRLF after the last record (the RFC makes it optional; emitting it keeps concatenation safe).
  • A field is quoted iff it contains the delimiter, a double quote, CR, or LF.
  • Embedded double quotes are escaped by doubling them.
  • The UTF-8 BOM is prepended by default so Excel on Windows decodes non-ASCII text correctly; set bom: false for pipelines that treat it as data.

Formula (CSV-injection) guard

Excel/Sheets treat a cell starting with =, +, -, @, TAB, or CR as a formula, which turns an exported customer-supplied string into code execution (=cmd|' /C calc'!A0) or data exfiltration (=IMPORTXML(...)) on the recipient's machine. This writer prefixes such a cell with a single quote ('), the conventional spreadsheet "treat as text" marker, and then quotes the field.

The guard applies to text-typed cells and to headers — never to number or money columns, whose values are produced by the SQL cast and must stay machine-parseable (a negative amount legitimately starts with -). Disable it with sanitizeFormulas: false only when the consumer downstream is not a spreadsheet.

On this page