Skip to content

fix: accept a byte order mark before the transaction CSV header - #146

Merged
jerelvelarde merged 2 commits into
CopilotKit:mainfrom
charan-rathore:fix/export-csv-bom
Oct 6, 2026
Merged

jerelvelarde merged 2 commits into
CopilotKit:mainfrom
charan-rathore:fix/export-csv-bom

Conversation

@charan-rathore

@charan-rathore charan-rathore commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

What changed

Pasting a transaction CSV that starts with a UTF-8 byte order mark (BOM) failed with "Invalid quoted CSV field" whenever the header row was quoted, for example "date","description","amount","category". Excel, Numbers and many bank exports write that mark at the start of the file, and it can come along when the text is copied.

The cause is in analyzeSpending. It parses the text character by character. The BOM (U+FEFF) was read as the first character of the first cell. When the next character was the opening quote, the parser saw text before the quote and rejected the field. Unquoted headers only worked because trim() happens to strip U+FEFF.

The fix drops a single leading U+FEFF before parsing. Nothing else about the parser changes, so the quote checks added in #69 still apply to everything after it.

Verification

  • Added a test that imports a BOM-prefixed CSV with both an unquoted and a quoted header. The quoted case fails before the fix with "Invalid quoted CSV field" and passes after it.
  • npx tsx --test tests/finance.test.ts tests/finance-headers.test.ts: 7 passed, 0 failed.
  • npx biome check on the two changed files: clean. npx tsc --noEmit: clean.
  • Not run: the full pnpm test, the mobile and platform builds, and the browser suites. This change touches only the server-side CSV parser and its test.

charan-rathore and others added 2 commits October 6, 2026 04:46
Signed-off-by: Charan Rathore <180254320+charan-rathore@users.noreply.github.com>

@jerelvelarde jerelvelarde left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Value: BOM-prefixed bank CSVs with quoted headers import correctly while existing quote validation remains intact. Seven finance/header tests passed. Template: explicit checks and untested paths. No actionable security finding. Updated-main diff reviewed; merge after required CI.

@jerelvelarde
jerelvelarde merged commit d344dc8 into CopilotKit:main Oct 6, 2026
7 checks passed
@charan-rathore
charan-rathore deleted the fix/export-csv-bom branch October 6, 2026 19:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants