Repository navigation
Read a URL encoded CSV in the #csv= fragment - #52
Merged
Merged
Conversation
`#csv=` took only base64url bytes, so the small hand-written link -- the one `?csv=` already takes -- had to go through a gzip pipeline before it could stay out of the request. It now takes percent-encoded CSV text too. Which encoding a link uses is read off the payload rather than declared: base64url spells everything in `A-Z a-z 0-9 - _ =`, and a CSV needs the comma between its date column and a value column, so a payload holding a character outside that alphabet is text and never a mangled base64url string. A base64url payload run through `encodeURIComponent` arrives with its padding as `%3D`, which is why the percent decoding happens first. `URLSearchParams` no longer reads the fragment. It decodes what it returns, which would decode a percent-encoded CSV here and again in `decodeCSVFragment` -- a cell holding the literal `%0A` would come back as a row break -- and it form-decodes, reading a `+` in a cell as a space. The raw value is handed over instead, and decoded exactly once. The percent decoding works escape by escape rather than over the whole string, because `decodeURIComponent` is all-or-nothing: one cell holding a bare `%` would otherwise cost the newlines in every row. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017hKewm4Qv8pVHVYDfBYbHg
aaronj1335
force-pushed
the
claude/csv-fragment-url-encoding-7q3xnw
branch
from
September 16, 2026 11:46
3727d3e to
1c9b46b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
#csv=took only base64url bytes, so the small hand-written link -- theone
?csv=already takes -- had to go through a gzip pipeline before itcould stay out of the request. It now takes percent-encoded CSV text too.
Which encoding a link uses is read off the payload rather than declared:
base64url spells everything in
A-Z a-z 0-9 - _ =, and a CSV needs thecomma between its date column and a value column, so a payload holding a
character outside that alphabet is text and never a mangled base64url
string. A base64url payload run through
encodeURIComponentarrives withits padding as
%3D, which is why the percent decoding happens first.URLSearchParamsno longer reads the fragment. It decodes what itreturns, which would decode a percent-encoded CSV here and again in
decodeCSVFragment-- a cell holding the literal%0Awould come back asa row break -- and it form-decodes, reading a
+in a cell as a space.The raw value is handed over instead, and decoded exactly once.
The percent decoding works escape by escape rather than over the whole
string, because
decodeURIComponentis all-or-nothing: one cell holding abare
%would otherwise cost the newlines in every row.Co-Authored-By: Claude Opus 5 noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_017hKewm4Qv8pVHVYDfBYbHg