Coverage for app/venv/lib/python3.14/site-packages/weblate/utils/csv.py: 100%
4 statements
« prev ^ index » next coverage.py v7.15.2, created at 2026-10-07 07:15 +0000
« prev ^ index » next coverage.py v7.15.2, created at 2026-10-07 07:15 +0000
1# Copyright © Michal Čihař <michal@weblate.org>
2#
3# SPDX-License-Identifier: GPL-3.0-or-later
5# The following characters are considered problematic for CSV files
6# - due to how they are interpreted by Excel
7# - due to the risk of CSV injection attacks
9from weblate.utils.unicodechars import WHITESPACE_CHARS
11CSV_FORMULA_TRIGGERS: set[str] = {"=", "+", "-", "@", "|", "%"}
13PROHIBITED_INITIAL_CHARS: set[str] = CSV_FORMULA_TRIGGERS | WHITESPACE_CHARS
15# Escape the whitespaces so they are rendered as their string representation instead of an actual character
16# This is later passed to format_html_join_comma
17PROHIBITED_INITIAL_CHARS_FOR_DISPLAY: tuple[tuple[str], ...] = tuple(
18 (char if char in CSV_FORMULA_TRIGGERS else f"\\u{ord(char):04x}",)
19 for char in PROHIBITED_INITIAL_CHARS
20)