refactor(microsoft-excel): export GRAPH_ID_PATTERN and deduplicate validation (#4174)

* refactor(microsoft-excel): export GRAPH_ID_PATTERN and reuse across routes

Export the shared regex pattern from utils.ts and import it in files/route.ts
and drives/route.ts instead of duplicating the inline pattern. Also reorders
the TSDoc comment to sit above getItemBasePath where it belongs.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* lint

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Waleed
2026-04-14 21:34:54 -07:00
committed by GitHub
co-authored by Claude Opus 4.6
parent 80095788fc
commit 22d4639f13
3 changed files with 7 additions and 5 deletions
@@ -4,6 +4,7 @@ import { authorizeCredentialUse } from '@/lib/auth/credential-access'
import { validatePathSegment } from '@/lib/core/security/input-validation'
import { generateRequestId } from '@/lib/core/utils/request'
import { getCredential, refreshAccessTokenIfNeeded } from '@/app/api/auth/oauth/utils'
import { GRAPH_ID_PATTERN } from '@/tools/microsoft_excel/utils'
export const dynamic = 'force-dynamic'
@@ -79,7 +80,7 @@ export async function GET(request: NextRequest) {
if (driveId) {
const driveIdValidation = validatePathSegment(driveId, {
paramName: 'driveId',
customPattern: /^[a-zA-Z0-9!_-]+$/,
customPattern: GRAPH_ID_PATTERN,
})
if (!driveIdValidation.isValid) {
return NextResponse.json({ error: driveIdValidation.error }, { status: 400 })
@@ -4,6 +4,7 @@ import { authorizeCredentialUse } from '@/lib/auth/credential-access'
import { validatePathSegment, validateSharePointSiteId } from '@/lib/core/security/input-validation'
import { generateRequestId } from '@/lib/core/utils/request'
import { refreshAccessTokenIfNeeded } from '@/app/api/auth/oauth/utils'
import { GRAPH_ID_PATTERN } from '@/tools/microsoft_excel/utils'
export const dynamic = 'force-dynamic'
@@ -69,7 +70,7 @@ export async function POST(request: NextRequest) {
if (driveId) {
const driveIdValidation = validatePathSegment(driveId, {
paramName: 'driveId',
customPattern: /^[a-zA-Z0-9!_-]+$/,
customPattern: GRAPH_ID_PATTERN,
})
if (!driveIdValidation.isValid) {
return NextResponse.json({ error: driveIdValidation.error }, { status: 400 })
+3 -3
View File
@@ -4,14 +4,14 @@ import type { ExcelCellValue } from '@/tools/microsoft_excel/types'
const logger = createLogger('MicrosoftExcelUtils')
/** Pattern for Microsoft Graph item/drive IDs: alphanumeric, hyphens, underscores, and ! (for SharePoint b!<base64> format) */
export const GRAPH_ID_PATTERN = /^[a-zA-Z0-9!_-]+$/
/**
* Returns the Graph API base path for an Excel item.
* When driveId is provided, uses /drives/{driveId}/items/{itemId} (SharePoint/shared drives).
* When driveId is omitted, uses /me/drive/items/{itemId} (personal OneDrive).
*/
/** Pattern for Microsoft Graph item/drive IDs: alphanumeric, hyphens, underscores, and ! (for SharePoint b!<base64> format) */
const GRAPH_ID_PATTERN = /^[a-zA-Z0-9!_-]+$/
export function getItemBasePath(spreadsheetId: string, driveId?: string): string {
const spreadsheetValidation = validatePathSegment(spreadsheetId, {
paramName: 'spreadsheetId',