983b7eff4b1c516c9cb7bb56cc1399216a127d51 max Wed Aug 19 04:02:39 2026 -0700 address v503 preview1 code review (#38141): escaping and oauth fixes Fixes the six items Brian raised reviewing the XSS sweep (#38057) and the BLAT-results group work (#38086): - hgGenome/configure.c, hgPal.c: drop htmlEncode() on cartWebStart title args; cartWebStart already escapes the title, so this was double-escaping. - hgSession.c doReSaveSession: htmlEncode the user name and pass the encoded name to getSessionLink (same fix already applied at line 1544). - hgUserSuggestion.c printInvalidForm: cgiEncode the five cart values echoed into the mailto: href (reachable on the robot/captcha path). - hgSearch.c: cgiEncode db for the hgTracks URL query parameter instead of reusing the JSON-escaped copy meant for the JS string literal. - hgLogin.c oauthReturn: clone oauth_provider before cartRemove frees it, so the later oauthFetchIdentity call is not a read-after-free. - customFactory.c checkGroup: only accept group=blat when blatResultsGroup is on, matching hgTracks; otherwise the group is never created and the track would orphan into 'other'. refs #38141, refs #38057, refs #38086 diff --git src/hg/hgPal/hgPal.c src/hg/hgPal/hgPal.c index 25e466fcbb0..93b91c94071 100644 --- src/hg/hgPal/hgPal.c +++ src/hg/hgPal/hgPal.c @@ -20,31 +20,31 @@ } void doMiddle(struct cart *cart) /* Set up globals and make web page */ { char *track = cartString(cart, "g"); char *chrom = cartOptionalString(cart, "c"); char *item = cartOptionalString(cart, "i"); int start = cartInt(cart, "l"); int end = cartInt(cart, "r"); char *database; char *genome; getDbAndGenome(cart, &database, &genome, NULL); struct sqlConnection *conn = hAllocConn(database); -cartWebStart(cart, database, "Other Species Alignments for %s %s",htmlEncode(track),htmlEncode(item)); // user input into title, escape (XSS) +cartWebStart(cart, database, "Other Species Alignments for %s %s",track,item); // cartWebStart escapes the title itself /* output the option selection dialog */ palOptions(cart, conn, addOurButtons, NULL); printf("For information about output data format see the " "<A HREF=\"../goldenPath/help/hgTablesHelp.html#FASTA\">User's Guide</A><BR>"); struct bed *bed; AllocVar(bed); bed->name = item; bed->chromStart = start; bed->chromEnd = end; bed->chrom = chrom; printf("<pre>");