onescales/google-sheet-api
Credit conversion $3Makes a Google Sheet Into a Public GET API (for reading and writing)
Makes a Google Sheet Into a Public GET API (for reading and writing)
No GitHub topics on this repo.
- JavaScript100.0%
Placement
Every place and its price$3
$3 from converted credits. Credits and grants are not card payments. This placement does not expire. Its rank holds until another repo spends more, and then this one moves down, never off. Taking the top of the board from here costs $15.
1 Review
This repository provides a very small, approachable Google Apps Script for exposing spreadsheet data as JSON and appending new rows through a web-app URL. The implementation has no external dependencies and is easy to copy into the Apps Script editor. It converts the first row into object keys, supports selecting a sheet by name, checks whether the requested sheet exists, avoids duplicate values in the first column, and returns readable status messages. The README walks through creating a sheet, deploying the script, constructing read and write URLs, and changing the example Users field. For a basic demonstration of Apps Script and Google Sheets integration, the project is easy to understand and reproduce. A full GPLv3 license is also included.
The main weakness is that the documented public deployment has no authentication or authorization. Anyone who discovers the web-app URL can read any named tab in the active spreadsheet and append data to it. The write operation also uses GET, so crawlers, browser previews, caching layers, or an accidentally opened link can modify the sheet. Writes should use doPost, require a secret or verified identity, restrict access to an explicit allowlist of sheet names, and validate request content. User-provided values should be protected against spreadsheet formula injection before being written. The duplicate check and append are separate operations without LockService, so concurrent requests can still insert duplicates.
The code would benefit from more structured API behavior. Missing sheets, invalid actions, and exceptions all return successful HTTP responses with inconsistent text or JSON bodies, making client-side error handling difficult. An empty sheet or duplicate header names can also break or silently overwrite fields. Input validation, a consistent response envelope, timestamps, request identifiers, and clear quota errors would improve reliability. There are no tests, CI workflows, appsscript.json manifest, clasp configuration, security documentation, or contribution guidance, and the application code has not changed since 2023. Adding unit tests around conversion, empty sheets, duplicate headers, concurrent writes, and malicious input would turn this useful tutorial into a safer reusable API template.
