# Fetching with a Javascript column—

**URL:** <https://community.glideapps.com/t/fetching-with-a-javascript-column/57683>\
**Category:** Community Resources\
**Created:** [February 9, 2023, 3:40am UTC](https://community.glideapps.com/t/fetching-with-a-javascript-column/57683 "2023-02-09T03:40:00Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robert\_Petitto](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/robert_petitto/32/25193_2.png) [@Robert\_Petitto](https://community.glideapps.com/u/Robert_Petitto)\
**Post date:** [February 9, 2023, 3:40am UTC](https://community.glideapps.com/t/fetching-with-a-javascript-column/57683/1 "2023-02-09T03:40:00Z")

</div>

> [@Fetch json with token](https://community.glideapps.com/t/fetch-json-with-token/53097/7):
>
> Hola!
> 
> I think it’s possible but if you share your cURL command (or Fetch syntax) we can try to fix it.
> 
> Your JS code might look like:
> 
> ```auto
> var data= await fetch('YOUR_URL', {
> method: 'POST',
> headers: {
> 'Content-Type': 'application/x-www-form-urlencoded',
> 'Authorization': 'YOUR_BearerToken'
> },
> });
> 
> const json = await data.text(); // or data.json();   
> return json
> 
> ```
> 
> Saludos!

This may be the greatest thing I’ve seen in a while. Solved a very important use case of mine…details to follow!

Note: As @Jeff_Hager mentions below, this should be used with extreme discretion.

---

<div class="post-metadata">

**Author:** ![Jeff\_Hager](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/jeff_hager/32/43_2.png) [@Jeff\_Hager](https://community.glideapps.com/u/Jeff_Hager)\
**Post date:** [February 9, 2023, 4:15am UTC](https://community.glideapps.com/t/fetching-with-a-javascript-column/57683/3 "2023-02-09T04:15:39Z")

</div>

I think one potential gotcha is that some snooping could easily reveal that header information, including the authentication token.

I believe a glide webhook is executed server side, so there is a little bit of protection there, especially if you utilize the webhook password, since it’s never revealed to the client. But a javascript column is executed client side, so it’s reasonably easy to debug that code as it runs.

Just something to consider depending on what kind of endpoint you are connecting to and how secure the data needs to be.

---

<div class="post-metadata">

**Author:** ![Robert\_Petitto](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/robert_petitto/32/25193_2.png) [@Robert\_Petitto](https://community.glideapps.com/u/Robert_Petitto)\
**Post date:** [February 9, 2023, 4:27am UTC](https://community.glideapps.com/t/fetching-with-a-javascript-column/57683/4 "2023-02-09T04:27:56Z")

</div>

Gotcha. Thanks. Ya, this is an internal app where the data is just whether a user is free or busy…so no sensitive data being passed…but will definitely keep this in mind.

---

<div class="post-metadata">

**Author:** ![gvalero](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/gvalero/32/1037_2.png) [@gvalero](https://community.glideapps.com/u/gvalero)\
**Post date:** [February 9, 2023, 11:31am UTC](https://community.glideapps.com/t/fetching-with-a-javascript-column/57683/5 "2023-02-09T11:31:33Z")

</div>

> [@Jeff\_Hager](#):
>
> But a javascript column is executed client side, so it’s reasonably easy to debug that code as it runs.

Hola Jeff,

I wonder if we use JS code parameters (p1, p2, p3) to hide sensitive information, will it improve security (or at least, make it harder the spying)?

Something like…

```auto
var data= await fetch(p1, {
    method: 'POST',
    headers: {
        'Content-Type': 'application/x-www-form-urlencoded',
        'Authorization': p2
    },
});

```

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [February 9, 2023, 11:47am UTC](https://community.glideapps.com/t/fetching-with-a-javascript-column/57683/6 "2023-02-09T11:47:42Z")

</div>

I’d be most concerned about the authentication token. With the code executed client side, there is no way to fully secure that, and so there is always the possibility it could leak.

I’d be less concerned about the data, as presumably whatever is returned will be displayed in the App. So there is probably no reason to try and hide that.

---

<div class="post-metadata">

**Author:** ![Jeff\_Hager](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/jeff_hager/32/43_2.png) [@Jeff\_Hager](https://community.glideapps.com/u/Jeff_Hager)\
**Post date:** [February 9, 2023, 1:12pm UTC](https://community.glideapps.com/t/fetching-with-a-javascript-column/57683/7 "2023-02-09T13:12:24Z")

</div>

Parameters won’t help. You can debug any computed column, including the javascript column, and see the data that’s passing through them. You can also set a watch on any variable in that code. There’s no way to fully secure what’s happening on the client end. I’m not saying it’s easy to see the data, but if you specifically know what to look for then you can still track down what those values are. I think Glide obfuscates their code, so it’s a mess to look at, but still can be debugged.

In comparison to webhooks, I’m pretty sure that webhooks run server side. That way glide can inject the webhook password into the header without the client device ever having knowledge of that password.

---

<div class="post-metadata">

**Author:** ![jpascuet](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/jpascuet/32/39486_2.png) [@jpascuet](https://community.glideapps.com/u/jpascuet)\
**Post date:** [January 4, 2024, 12:12pm UTC](https://community.glideapps.com/t/fetching-with-a-javascript-column/57683/8 "2024-01-04T12:12:50Z")

</div>

Hi all, I have some problems with this fetchs calls. My code works but when I try to add some functions never works again.

I try to fetch a GET or POST service implemented in the gsheet of the glide project, so, all are vinculated.

My glide script in java is the following, with a develope URL for web app in appscript:

var url = ‘[https://script.google.com/macros/s/AKblablablablablablablabla/dev?action=do](https://script.google.com/macros/s/AKblablablablablablablabla/dev?action=do)’;  
var options = {  
method: ‘GET’,  
headers: { //note, I try with many headers/content-types  
‘Content-Type’: ‘application/x-www-form-urlencoded’,  
},  
};

//FETCH  
var data = await fetch(url, options);

//RESPONSE  
const json = await data.text();  
return json;

Always I get “Failed to fetch”  
The doGet method in de google sheet do nothing special, for testing porpouse.  
function doGet(e) {  
Logger.log(‘doGet’, Date());  
return ContentService.createTextOutput(‘0’).setMimeType(ContentService.MimeType.TEXT);  
}

Anyone knows why this scenario works two days ago but nothing happend today when I try to work with them? Because almost once this works means no token info are needed.

I don’t want to work with flags in cells to trigger appscript events, I want to call GET or POST app web.

Any help?

---

<div class="post-metadata">

**Author:** ![gvalero](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/gvalero/32/1037_2.png) [@gvalero](https://community.glideapps.com/u/gvalero)\
**Post date:** [January 4, 2024, 12:48pm UTC](https://community.glideapps.com/t/fetching-with-a-javascript-column/57683/9 "2024-01-04T12:48:49Z")

</div>

> [@jpascuet](#):
>
> var url = ‘[https://script.google.com/macros/s/AKblablablablablablablabla/dev?action=do’](https://script.google.com/macros/s/AKblablablablablablablabla/dev?action=do%E2%80%99);

Hola Juan!

At first glance, it seems your web app version was erased or has some syntax error (URL).

Also, you are using a development/test version and it will work with Google tools (e.g. Chrome) but with Glide, you must use a production version already deployed and authorized

So, the URL of your deployed web application must contain the “/exec” parameter and not “ **/dev** ”. Something like:

> ‘[https://script.google.com/macros/s/AKblablablablablablablabla/exec?action=do’](https://script.google.com/macros/s/AKblablablablablablablabla/exec?action=do%E2%80%99);

Espero te sirva, saludos!

---

<div class="post-metadata">

**Author:** ![jpascuet](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/jpascuet/32/39486_2.png) [@jpascuet](https://community.glideapps.com/u/jpascuet)\
**Post date:** [January 4, 2024, 1:03pm UTC](https://community.glideapps.com/t/fetching-with-a-javascript-column/57683/10 "2024-01-04T13:03:45Z")

</div>

You right! with the production URL the fetch works fine… is a petty because I need to work in the appscript a while and I need to test from Glide, so I will to deploy for each change. But, it works  
Thanks!
