Skip to content

Browsers and CSP

Use dist/xlsx.full.min.js for a full browser distribution. It creates the XLSX global and includes the codepage tables. Copy it from the package to your web server.

<script src="xlsx.full.min.js"></script>
<script>
const ws = XLSX.utils.aoa_to_sheet([["Item", "Count"], ["Bolt", 3]]);
const wb = XLSX.utils.book_new();
XLSX.utils.book_append_sheet(wb, ws, "Items");
XLSX.writeFile(wb, "items.xlsx");
</script>

writeFile starts a browser download. readFile cannot read a browser user’s disk path; use a file input and File.arrayBuffer() instead. See Quick start.

The engine is a WebAssembly module embedded in the JavaScript files. It does not fetch a separate .wasm file. Its synchronous compilation requires a policy that allows WebAssembly compilation:

Content-Security-Policy: script-src 'self' 'wasm-unsafe-eval'

This example permits same-origin scripts and WebAssembly compilation. Adapt it to your application’s other needs. Inline script examples also need a nonce or hash under such a policy; moving the application code into a same-origin script is another option.

Without 'wasm-unsafe-eval' (or the broader 'unsafe-eval'), loading the library throws an error containing WebAssembly compilation failed. There is no JavaScript fallback. The original JavaScript build does not need this directive.

Chromium and Firefox pages and Web Workers were tested. Safari and other browsers were not tested. The library needs standard WebAssembly 1.0, ES2017 features, typed arrays, and atob or Buffer. It does not require WebAssembly threads, SIMD, GC, or exceptions. TextEncoder and TextDecoder are used when available.

dist/shim.min.js provides ES5 polyfills for surrounding application code. It does not make the library work in a browser without WebAssembly.

See Distribution files for the reduced mini build and Runtime support for the tested environments.