From 2ae370a34de5fc4cdc92a4db24388c573a6a0e23 Mon Sep 17 00:00:00 2001 From: zkldi <20380519+zkldi@users.noreply.github.com> Date: Mon, 6 Feb 2023 22:22:35 +0000 Subject: [PATCH] fix: unwrap quotes in naive csv --- server/src/utils/naive-csv-parser.ts | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/server/src/utils/naive-csv-parser.ts b/server/src/utils/naive-csv-parser.ts index 5b214cc19..b7dc8211c 100644 --- a/server/src/utils/naive-csv-parser.ts +++ b/server/src/utils/naive-csv-parser.ts @@ -57,7 +57,20 @@ export function NaiveCSVParse(csvBuffer: Buffer, logger: KtLogger) { for (const [rowNumber, data] of Object.entries(csvData).slice(1)) { // @security: This should probably be safetied from DOSing - const cells = data.split(","); + const cells = data.split(",").map((e) => { + // we want to remove quotes from anything that is *absolutely* + // surrounded by quotes. + // Even though we are naively parsing csvs, it seems like atleast + // one person managed to mangle their inputs such that this happened. + const isSurroundedByQuotes = /^"(.*)"$/u.exec(e) as [string, string] | null; + + if (isSurroundedByQuotes) { + return isSurroundedByQuotes[1]; // unwrap the quotes + } + + // do nothing + return e; + }); // an empty string split on "," is an array with one empty value. if (cells.length === 1) {