Skip to content

Releases: ilbee/csv-response

v1.9.0

Choose a tag to compare

@ilbee ilbee released this 27 Mar 15:46

Added

  • Optional maxRows parameter on both CSVResponse and StreamedCSVResponse to limit the number of rows and prevent unbounded memory usage (throws OverflowException when exceeded)
  • Explicit InvalidArgumentException when a data value is an object without __toString(), instead of a raw PHP error

Security

  • StreamedCSVResponse now uses HeaderUtils::makeDisposition() for the Content-Disposition header (aligned with CSVResponse)

Full Changelog: 1.8.1...1.9.0

v1.8.1

Choose a tag to compare

@ilbee ilbee released this 27 Mar 15:32

Security

  • Use Symfony's HeaderUtils::makeDisposition() instead of manual sprintf for Content-Disposition header, preventing HTTP header injection via crafted filenames (RFC 6266 compliant)

Closes #24

Full Changelog: 1.8.0...1.8.1

1.8.0

Choose a tag to compare

@ilbee ilbee released this 27 Mar 15:24

Changed

  • Dropped Symfony 4.x support (EOL since November 2023)
  • Updated symfony/http-foundation constraint to ^5.4 || ^6.4 || ^7.0 || ^8.0
  • Extended CI matrix to test Symfony 5.4 and 8.0

Closes #28

1.7.1

Choose a tag to compare

@ilbee ilbee released this 27 Mar 15:13
57d9065

Security Fixes

  • HTTP Header Injection via filename (HIGH): Sanitize fileName to strip CRLF, tabs, quotes, and null bytes; apply basename() to prevent path traversal — blocks Content-Disposition header injection
  • CSV Injection in column headers (MEDIUM): Apply formula sanitization to CSV headers (not just cell values) when sanitizeFormulas is enabled — prevents spreadsheet formula injection via =, +, -, @, tab, CR, LF prefixes

Tests

  • 4 new tests covering header injection, path traversal, empty filename fallback, and formula injection in headers

1.7.0

Choose a tag to compare

@ilbee ilbee released this 27 Mar 13:50
2b57421

What's New

StreamedCSVResponse (#12)

New StreamedCSVResponse class for large CSV exports without memory buffering. Extends Symfony's StreamedResponse and writes rows directly to php://output.

// Stream large datasets without hitting memory limits
return new StreamedCSVResponse($data);

// Works with callables for lazy data loading
return new StreamedCSVResponse(function () {
    return $repository->findAllAsGenerator();
});

Shared architecture

  • Extracted CSVResponseInterface with shared constants
  • Extracted CSVResponseTrait with shared logic (value conversion, formula sanitization)
  • CSVResponse refactored to use interface + trait — zero BC break
  • Both classes now accept callable data sources (in addition to iterable)

1.6.1

Choose a tag to compare

@ilbee ilbee released this 27 Mar 13:19
dbe4a70

Security

  • Sanitize CSV values to prevent formula injection (#23) — prefix dangerous cell values starting with =, +, -, @, \t, \r, \n with a single quote
  • New sanitizeFormulas constructor option (enabled by default, can be disabled for trusted data)

1.6.0

Choose a tag to compare

@ilbee ilbee released this 27 Mar 11:03

What's new

  • Configurable DateTime format — new $dateFormat parameter to customize how DateTimeInterface values are formatted (#14)
  • Disable header row — new $includeHeaders parameter to omit the header row from CSV output (#13)
  • Updated README with full constructor documentation

1.5.0

Choose a tag to compare

@ilbee ilbee released this 27 Mar 10:42
21964e9

Added

  • Optional UTF-8 BOM for Excel compatibility (#10)
    New $addBom parameter in constructor (default false).
    When enabled, prepends UTF-8 BOM so Excel correctly displays accented characters (é, è, ü, etc.)

Changed

  • Constructor parameters now use multi-line formatting

1.4.0

Choose a tag to compare

@ilbee ilbee released this 27 Mar 10:10

What's Changed

Bug Fixes

  • Fix DateTimeImmutable not being formatted — use instanceof \DateTimeInterface instead of get_class() string comparison (#9, #17)
  • Handle null, boolean, and nested array values gracefully (#15, #18)
    • null → empty string
    • bool → "true" / "false" strings
    • Nested arrays → InvalidArgumentException with clear message

Improvements

  • Modernize CI: add PHPStan, php-cs-fixer, split jobs (#16)
  • Rewrite README with modern structure and documentation
  • Add PR templates and modernize issue templates

Full Changelog: 1.3.0...1.4.0

Compatibility with PHP 8.4

Choose a tag to compare

@ilbee ilbee released this 10 Mar 09:50
85aae36
1.3.0

Extends action for new PHP Versions