- richTextPrefix visits at most maxCellTextChars + 1 runs. An empty run adds
no text, so a length check alone walked every run of a shared string for
every cell referencing it, on every tile.
- Two or more unsupported number format warnings in a tile fold into one
"N unsupported number formats" entry, and the notice bar has a max-height
and scrolls.
- General-format and unsupported-format numbers render at 15 significant
digits, as Excel does (0.1+0.2 shows 0.3).
- TIME_FORMAT accepts a trailing AM/PM, so h:mm AM/PM renders as 2:30 PM
instead of falling back to a date.
- SPREADSHEET_ASSET_VERSION refreshed.
- Normalize the value shapes ExcelJS loads before formatting: Date cells are
formatted from their serial (UTC), so they no longer render as a local-time
string a day early at negative UTC offsets; rich text joins its runs,
hyperlinks show their text, error values show the error, and formula and
shared-formula results (including error results) recurse. Excel serials are
rounded to whole milliseconds so 00:05 no longer shows as 00:04.
- sendTile() skips hidden rows and columns, and at the 2500-cell cap returns a
truncated tile with a warning instead of failing the whole preview.
- ExcelJS now parses a STORE-only archive rebuilt from exactly the entries
admitXlsx() inflated and counted, never the fetched bytes. Admission walks
local headers while JSZip reads the central directory, so overlapping
entries could show the two readers different sheets. A duplicate local
entry name is refused. The theme fallback reads the admitted entry too.
- Row and column headings take their size from the same axis math as cells.
- Document the admission, worker-only loading and SPREADSHEET_ASSET_VERSION
rules in architecture-invariants, and list .xlsx in the attachments panel
help and the `codeman attach` error text (built from the accepted list).
xlsx files were download-only. Add a read-only, virtualized preview (sheet
tabs, number formats, merges, theme colours) parsed entirely in a browser
Web Worker with exceljs and fflate, loaded only when a spreadsheet is
opened. The workbook is checked against ZIP-bomb, entry and cell limits
before exceljs loads; cell text is written with textContent, formulas are
never evaluated and nothing referenced by the workbook is fetched. On the
server xlsx only joins the existing allowlist and classification, with a
10 MB cap on ?preview=true. xls and ods stay download-only.