Security notes
The library reads and writes spreadsheet data. It does not execute macros, access the
network, or resolve external entities. VBA content can be retained as data with bookVBA;
preserving it does not execute it.
Untrusted files
Section titled “Untrusted files”Malformed input can throw. Catch those errors, limit accepted file sizes, and apply your application’s resource limits. A compressed workbook may expand substantially in memory. Do not assume a small uploaded file will be cheap to parse.
For a web application, use a worker for large inputs. For a service, apply limits appropriate
to the workload. sheetRows limits parsed rows, but is not a complete memory or security boundary.
Generated content
Section titled “Generated content”Spreadsheet cells can contain formulas and hyperlinks. Preserving them is not the same as
checking whether they are safe for your users to open or follow. Apply your own rules before
exporting untrusted data. Text beginning with =, +, -, or @ may be interpreted as a
formula by an application opening CSV; decide whether to neutralize it for your export.
When rendering HTML output in a web page, treat it as generated content and follow your application’s HTML safety policy. Do not substitute untrusted HTML for a plain cell value.
Protection and encryption
Section titled “Protection and encryption”Worksheet protection controls spreadsheet editing permissions. It is not file encryption.
The package does not provide file encryption or the utils.hash_password and
utils.test_password runtime functions. Type declarations for those helpers are retained
for compatibility, not evidence that the runtime implements them.
Browser policy
Section titled “Browser policy”WebAssembly compilation needs 'wasm-unsafe-eval' in script-src. Prefer that narrower
permission to 'unsafe-eval'. See Browsers and CSP.