Skip to content

basalt / drives-microsoft/src / MICROSOFT_DOWNLOAD_HOSTS

Variable: MICROSOFT_DOWNLOAD_HOSTS ​

> const MICROSOFT_DOWNLOAD_HOSTS: readonly string[]

Defined in: drives-microsoft/src/index.ts:156

Hosts a @microsoft.graph.downloadUrl (or a /content redirect) can point at, as .suffix entries — never bare parents.

.sharepoint.com matches contoso-my.sharepoint.com and not sharepoint.com, and critically not evilsharepoint.com, which a naive endsWith would wave through. The guard re-validates every hop anyway: the allowlist is what bounds where, the SSRF guard is what bounds what address that host resolves to.

  • .files.1drv.com — personal OneDrive content hosts.
  • .sharepoint.com — OneDrive for Business and SharePoint libraries.
  • .svc.ms — the CDN Graph redirects /content through for some tenants.

An operator who knows their tenant can narrow this to one exact host with MicrosoftDriveOptions.downloadHosts, which is strictly better and takes one line.

Released under the MIT License.