Distinguish a broken row from a short file
For one invented report, specify column names, record IDs and expected record count. Parse the downloaded file with a CSV parser rather than counting lines: a quoted field may contain a newline. Determine whether all records arrived before changing the serializer or increasing response limits.
- Include a comma, quote, newline and non-ASCII text in synthetic fields.
- Keep a parser result and ID comparison beside the HTTP result.
- A downloaded filename or status 200 is not proof the entire report reached its consumer.
Serialize raw fields through the CSV library
Django's official guide uses Python csv.writer and explains that it handles comma and quote escaping. Hand-joining fields with commas can shift columns; applying HTML escaping answers a different question. Do not infer that CSV quoting prevents spreadsheet formulas: choose a separate owner-approved handling policy for untrusted cell contents.
- Assert the same number and order of fields after parsing each row.
- Keep encoding and destination import expectations explicit.
- Do not use real names or financial records to test quoting.
Large-response completion is a separate branch
The guide proposes StreamingHttpResponse and generators for large reports. Streaming is not a guarantee against timeouts, buffering or partial downloads. If small correctly serialized fixtures pass but only a large transfer fails, preserve that observation and ask the existing operator to define a bounded performance/delivery investigation rather than pretend the quoting patch solved it.
- An authored correctness check compares all expected synthetic IDs and columns after download.
- Do not claim measured speed, memory savings or completed delivery; none was executed here.
Non-fit and priced route
One deterministic CSV-format defect may fit fix-one-bug-with-regression-test, from £295 after bounded reproduction and a fixed quote. Profiling, load testing and speed guarantees are explicitly outside that offer. A new small CSV export feature may fit ship-one-feature-with-running-preview, from £750 after agreeing its fields, review route and checks. Private reporting data, a broad export pipeline or financial reconciliation needs separate scope.
- Keep downloads access-controlled where the report is private; CSV format does not authorise disclosure.
- Initial contact needs invented fields and expected parsed output, not an export or repository access.
Sources and limits
- Django 5.2 CSV output guide; BSD-licensed project documentation Checked 2026-10-11.
- Python csv.writer handles quoting of commas and quotes.
- StreamingHttpResponse and a generator are documented options for large CSV responses.
- CSV quoting guidance does not establish protection from spreadsheet formula interpretation.
- Current single-bug offer excludes profiling and performance promises Checked 2026-10-11.
- Current one-feature preview offer Checked 2026-10-11.