9ad04e0a0b06ec3c4f09ef1b6c3ce6be79b61c68
braney
  Sun Aug 16 11:56:56 2026 -0700
cart: validate file names read back out of the cart

Several cart variables hold the name of a file the server created for a user.
Route them through one shared check, isServerUserFilePath(), which accepts the
trash directory, the session-data directories and myVariantsDataDir, and apply
it both where values enter the cart and where the file names are used.

A few of these variables may instead hold a remote URL.  Those get their own
list and isServerUserFileOrUrl(), because the code that reads them chooses
between a fetch and a local open by looking for a protocol.

Consolidates two hand-rolled copies of the same test in blatShare.c and
customFactory.c, and drops the weaker private copy in sessionData.c.

Adds hg/utils/cartFileVarCatalog, a registry that scans the tree for a cart
value reaching a file call and reconciles what it finds against the lists in
cart.c, so a new one of these cannot be added without somebody noticing.  Its
--reconcile is quiet enough for the nightly cron the other catalogs use, and it
is what turned up seven of the names now on those lists.

refs #37623

diff --git src/hg/visiGene/hgVisiGene/hgVisiGene.c src/hg/visiGene/hgVisiGene/hgVisiGene.c
index 6965e99ecd7..4f0f75fe2b3 100644
--- src/hg/visiGene/hgVisiGene/hgVisiGene.c
+++ src/hg/visiGene/hgVisiGene/hgVisiGene.c
@@ -204,30 +204,32 @@
 	    }
 	}
     freez(&match);
     }
 hashFree(&uniqHash);
 slReverse(&newList);
 return newList;
 }
 
 static void doThumbnails(struct sqlConnection *conn)
 /* Write out list of thumbnail images. */
 {
 char *sidUrl = cartSidUrlString(cart);
 char *listSpec = cartUsualString(cart, hgpListSpec, "");
 char *matchFile = cartString(cart, hgpMatchFile);
+if (!isServerUserFilePath(matchFile))
+    errAbort("Invalid match file");
 struct visiMatch *matchList = NULL, *match;
 int maxCount = 25, count = 0;
 int startAt = cartUsualInt(cart, hgpStartAt, 0);
 int imageCount;
 
 htmlSetStyle(
 "<STYLE TYPE=\"text/css\">\n"
 "  BODY {margin: 2px}\n"
 "  </STYLE>\n"
 );
 htmlSetBgColor(0xC0C0D6);
 htmStart(stdout, "doThumbnails");
 matchList = readMatchFile(matchFile);
 imageCount = slCount(matchList);
 if (imageCount > 0)