basalt / drives-microsoft/src / MICROSOFT_DOWNLOAD_HOSTS
Variable: MICROSOFT_DOWNLOAD_HOSTS
> const MICROSOFT_DOWNLOAD_HOSTS: readonly string[]
Defined in: drives-microsoft/src/index.ts:156
Hosts a @microsoft.graph.downloadUrl (or a /content redirect) can point at, as .suffix entries — never bare parents.
.sharepoint.com matches contoso-my.sharepoint.com and not sharepoint.com, and critically not evilsharepoint.com, which a naive endsWith would wave through. The guard re-validates every hop anyway: the allowlist is what bounds where, the SSRF guard is what bounds what address that host resolves to.
.files.1drv.com— personal OneDrive content hosts..sharepoint.com— OneDrive for Business and SharePoint libraries..svc.ms— the CDN Graph redirects/contentthrough for some tenants.
An operator who knows their tenant can narrow this to one exact host with MicrosoftDriveOptions.downloadHosts, which is strictly better and takes one line.