Repository navigation
Releases: ilbee/csv-response
Releases · ilbee/csv-response
Release list
v1.9.0
Added
- Optional
maxRowsparameter on bothCSVResponseandStreamedCSVResponseto limit the number of rows and prevent unbounded memory usage (throwsOverflowExceptionwhen exceeded) - Explicit
InvalidArgumentExceptionwhen a data value is an object without__toString(), instead of a raw PHP error
Security
StreamedCSVResponsenow usesHeaderUtils::makeDisposition()for theContent-Dispositionheader (aligned withCSVResponse)
Full Changelog: 1.8.1...1.9.0
v1.8.1
1.8.0
1.7.1
Security Fixes
- HTTP Header Injection via filename (HIGH): Sanitize
fileNameto strip CRLF, tabs, quotes, and null bytes; applybasename()to prevent path traversal — blocks Content-Disposition header injection - CSV Injection in column headers (MEDIUM): Apply formula sanitization to CSV headers (not just cell values) when
sanitizeFormulasis enabled — prevents spreadsheet formula injection via=,+,-,@, tab, CR, LF prefixes
Tests
- 4 new tests covering header injection, path traversal, empty filename fallback, and formula injection in headers
1.7.0
What's New
StreamedCSVResponse (#12)
New StreamedCSVResponse class for large CSV exports without memory buffering. Extends Symfony's StreamedResponse and writes rows directly to php://output.
// Stream large datasets without hitting memory limits
return new StreamedCSVResponse($data);
// Works with callables for lazy data loading
return new StreamedCSVResponse(function () {
return $repository->findAllAsGenerator();
});Shared architecture
- Extracted
CSVResponseInterfacewith shared constants - Extracted
CSVResponseTraitwith shared logic (value conversion, formula sanitization) CSVResponserefactored to use interface + trait — zero BC break- Both classes now accept
callabledata sources (in addition toiterable)
1.6.1
1.6.0
1.5.0
Added
- Optional UTF-8 BOM for Excel compatibility (#10)
New$addBomparameter in constructor (defaultfalse).
When enabled, prepends UTF-8 BOM so Excel correctly displays accented characters (é, è, ü, etc.)
Changed
- Constructor parameters now use multi-line formatting
1.4.0
What's Changed
Bug Fixes
- Fix
DateTimeImmutablenot being formatted — useinstanceof \DateTimeInterfaceinstead ofget_class()string comparison (#9, #17) - Handle
null,boolean, and nested array values gracefully (#15, #18)null→ empty stringbool→"true"/"false"strings- Nested arrays →
InvalidArgumentExceptionwith clear message
Improvements
- Modernize CI: add PHPStan, php-cs-fixer, split jobs (#16)
- Rewrite README with modern structure and documentation
- Add PR templates and modernize issue templates
Full Changelog: 1.3.0...1.4.0
Compatibility with PHP 8.4
1.3.0 Extends action for new PHP Versions