Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
google-drive-sheets
Advanced tools
Google Sheets API -- simple interface to interact with Google Sheets
A simple Node.js library to read and manipulate data in Google Spreadsheets.
Works without authentication for read-only sheets or with auth for adding/editing/deleting data. Supports both list-based and cell-based feeds.
You can find more information about the Google Sheets API here.
$ npm install --save google-drive-sheets
var GoogleSheets = require('google-drive-sheets');
// spreadsheet key is the long id in the sheets URL
var mySheet = new GoogleSheets('<spreadsheet key>');
// Without auth -- read only
// IMPORTANT: See note below on how to make a sheet public-readable!
// # is worksheet id - IDs start at 1
mySheet.getRows(1, function(err, rowData) {
console.log('Pulled in '+rowData.length + ' rows');
});
// With auth -- read + write
// see below for authentication instructions
var creds = require('./google-generated-creds.json');
// OR, if you cannot save the file locally (like on heroku)
var creds = {
client_email: 'yourserviceaccountemailhere@google.com',
private_key: 'your long private key stuff here'
}
mySheet.useServiceAccountAuth(creds, function(err) {
// getInfo returns info about the sheet and an array of "worksheet" objects
mySheet.getInfo(function(err, sheetInfo) {
console.log(sheetInfo.title + ' is loaded');
// use worksheet object if you want to stop using the # in your calls
var sheet1 = sheetInfo.worksheets[0];
sheet1.getRows(function(err, rows) {
rows[0].colname = 'new val';
rows[0].save(); //async and takes a callback
rows[0].del(); //async and takes a callback
});
});
// column names are set by google and are based
// on the header row (first row) of your sheet
mySheet.addRow(2, { colname: 'col value' });
mySheet.getRows(2, {
start: 100, // start index
num: 100, // number of rows to pull
orderby: 'name' // column to order results by
}, function(err, rowData) {
// do something...
});
})
IMPORTANT: Google recently deprecated their ClientLogin (username+password) access, so things are slightly more complicated now. Older versions of this module supported it, so just be aware that things changed.
By default, this module makes unauthenticated requests and can therefore only access spreadsheets that are "public".
The Google Spreadsheets Data API reference and developers guide is a little ambiguous about how you access a "published" public Spreadsheet.
If you wish to work with a Google Spreadsheet without authenticating, not only must the Spreadsheet in question be visible to the web, but it must also have been explicitly published using "File > Publish to the web" menu option in the google spreadsheets GUI.
Many seemingly "public" sheets have not also been "published" so this may cause some confusion.
This is a 2-legged OAuth method and designed to be "an account that belongs to your application instead of to an individual end user". Use this for an app that needs to access a set of documents that you have full access to. (read more)
Setup Instructions
GoogleSheets
The main class that represents an entire spreadsheet.
new GoogleSheets(sheet_id, [auth], [options])
Create a new Google spreadsheet object.
sheet_id
-- the ID of the spreadsheet (from its URL)auth
- (optional) an existing auth tokenoptions
- (optional)
visibility
- defaults to public
if anonymousprojection
- defaults to values
if anonymousGoogleSheets.useServiceAccountAuth(account_info, callback)
Uses a service account email and public/private key to create a token to use to authenticated requests. Normally you would just pass in the require of the json file that Google generates for you when you create a service account.
See the "Authentication" section for more info.
If you are using heroku or another environment where you cannot save a local file, you may just pass in an object with
client_email
-- your service account's email addressprivate_key
-- the private key found in the JSON fileInternally, this uses a JWT client to generate a new auth token for your service account that is valid for 1 hour. The token will be automatically regenerated when it expires.
GoogleSheets.setAuthToken(id)
Use an already created auth token for all future requets.
GoogleSheets.getInfo(callback)
Get information about the spreadsheet. Calls callback passing an object that contains:
title
- the title of the documentupdated
- last updated timestampauthor
- auth info in an object
name
- author nameemail
- author emailworksheets
- an array of SpreadsheetWorksheet
objects (see below)GoogleSheets.getRows(worksheetId, options, callback)
Get an array of row objects from the sheet.
worksheetId
- the index of the sheet to read from (index starts at 1)options
(optional)
start-index
- start reading from row #max-results
- max # of rows to read at onceorderby
- column key to order byreverse
- reverse resultsquery
- send a structured query for rows (more info)callback(err, rows)
- will be called with an array of row objects (see below)GoogleSheets.addRow(worksheetId, new_row, callback)
Add a single row to the sheet.
worksheetId
- the index of the sheet to add to (index starts at 1)new_row
- key-value object to add - keys must match the header row on your sheetcallback(err)
- callback called after row is addedGoogleSheets.getCells(worksheetId, options, callback)
Get an array of cell objects.
worksheetId
- the index of the sheet to add to (index starts at 1)options
(optional)
min-row
- row range min (uses #s visible on the left)max-row
- row range maxmin-col
- column range min (uses numbers, not letters!)max-col
- column range maxreturn-empty
- include empty cells (boolean)SpreadsheetWorksheet
Represents a single "sheet" from the spreadsheet. These are the different tabs/pages visible at the bottom of the Google Sheets interface.
This is a really just a wrapper to call the same functions on the spreadsheet without needing to include the worksheet id.
Properties:
id
- the ID of the sheettitle
- the title (visible on the tabs in Google's interface)rowCount
- number of rowscolCount
- number of columnsSpreadsheetWorksheet.getRows(options, callback)
See above.
SpreadsheetWorksheet.getCells(options, callback)
See above.
SpreadsheetWorksheet.addRow(new_row, callback)
See above.
SpreadsheetRow
Represents a single row from a sheet.
You can treat the row as a normal javascript object. Object keys will be from the header row of your sheet, however the Google API mangles the names a bit to make them simpler. It's easiest if you just use all lowercase keys to begin with.
SpreadsheetRow.save( callback )
Saves any changes made to the row's values.
SpreadsheetRow.del( callback )
Deletes the row from the sheet.
SpreadsheetCell
Represents a single cell from the sheet.
SpreadsheetCell.setValue(val, callback)
Set the value of the cell and save it.
SpreadsheetCell.del(callback)
Clear the cell -- internally just calls .setValue('', callback)
This is based of the code by samcday. Original version here
[1.1.0][1.1.0] - 2015-09-08
.editorconfig
, .jshintrc
and .jscsrc
files, and enforced style guide.FAQs
Google Sheets API -- simple interface to interact with Google Sheets
The npm package google-drive-sheets receives a total of 22 weekly downloads. As such, google-drive-sheets popularity was classified as not popular.
We found that google-drive-sheets demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.