CSV Imports and Exports: What Actually Works
Letting users upload and download data as spreadsheet-friendly CSV files.
The key figures
- Encoding
- character encoding mismatches corrupt names and symbols
- Formula injection
- spreadsheet software can execute cell contents
- Large files
- need streaming rather than loading into memory
- Validation
- imports need row-level error reporting
Why this is worth getting right
CSV is the universal business data format, and imports are a common source of corrupted data and security problems.
Do this, not that
Do
- Stream large files instead of loading them
- Validate rows and report errors clearly
- Escape values that could be read as formulas
- Declare encoding explicitly
- Provide a template file
Don’t
- Trusting uploaded data
- Silent partial imports
- Exports that break in spreadsheet software
- Imports processed during web requests
When to bring in help
Our advice Bring in help when imports touch critical business data.
Where this comes from
- OWASP — CSV Injection
- Laravel Documentation — File storage
The figures and practices above come from the sources listed.
Working on something like this?
We take on Web Design & Development work for teams who want it done once, properly. Tell us what you are building and we will tell you honestly whether we are the right studio for it. Start a project.
Where to go next
Spotted something wrong? Report an error on this page. We correct on the page and say what changed.