d898b4820087cccd79e240153bc310856bb89310 braney Sat Sep 19 18:22:49 2026 -0700 hVarSubstHtmlTester: pin which variables a description page may use A native description page has been through hgTrackDb already, which resolved everything it could and deferred only ${hgsid}, so the render pass acts on that one variable and only in braces: hgTrackDb collapses an escaped $$hgsid to a literal $hgsid, and acting on the bare form here would expand the very thing the author escaped. A hub's page has never been substituted, so the whole hub list is resolved at render time, and $hgsid is deliberately not on that list. A hub page is only lightly sanitized -- an with an http src survives -- so a page carrying would hand the reader's session id to the hub's own server, and a session id alone is enough to read and write that cart. The page renders the same either way and the request goes to somebody else's host, so nothing about this is visible here. The test builds a cart by hand rather than opening one. That is not a shortcut, it is the point: a cartless version of this test was written first, and adding hgsid back to hubHtmlVars changed not one line of its output, because the check that recognises a variable also asks whether this call can resolve it, and with no cart it cannot. cartSessionId reads two fields, so a struct built in the test is enough and no database is involved. Watched to fail and then pass: with hgsid back on the hub list, both hub cases come back with the session id substituted into the img src. Recorded as sandbox-ab in utils/testRegistry. refs #38283, refs #38391 diff --git src/hg/lib/tests/makefile src/hg/lib/tests/makefile index 526d235e3c0..239a37ad450 100644 --- src/hg/lib/tests/makefile +++ src/hg/lib/tests/makefile @@ -12,31 +12,32 @@ ${BIN_DIR}/pslReaderTester \ ${BIN_DIR}/quickLiftTester \ ${BIN_DIR}/sessionDataTester \ ${BIN_DIR}/trashDirTester \ # ${BIN_DIR}/annoGratorTester \ ${BIN_DIR}/binTest \ ${BIN_DIR}/customTrackTester \ ${BIN_DIR}/hgvsTester \ ${BIN_DIR}/sqlCheck ${BIN_DIR}/%: %.c ${MYLIBS} @${MKDIR} ${BIN_DIR} ${CC} ${CC_PROG_OPTS} -o $@ $*.c ${MYLIBS} $L #test: binTest spDbTest hdbTest genePredTest pslReaderTest annoGratorTest customTrackTest hgvsTest -test: binTest quickLiftTest sessionDataTest trashDirTest mallocTopPadTest bedItemRgbTest spDbTest hdbTest genePredTest pslReaderTest customTrackTest hgvsTest +test: binTest quickLiftTest sessionDataTest trashDirTest mallocTopPadTest bedItemRgbTest \ + hVarSubstHtmlTest spDbTest hdbTest genePredTest pslReaderTest customTrackTest hgvsTest rm -r output echo tested all mkdirs: @${MKDIR} output ${BIN_DIR} loaders: ln -sf ${CGI_BIN}/loader . spDbTest: ${BIN_DIR}/spDbTest mkdirs ${BIN_DIR}/spDbTest sp121210 Q9FFH7 > output/spDbTest ${BIN_DIR}/spDbTest sp121210 P29312 >> output/spDbTest diff expected/spDbTest output/spDbTest hdbTest: ${BIN_DIR}/hdbTest mkdirs @@ -107,21 +108,26 @@ diff expected/mallocTopPadTest output/mallocTopPadTest # bedItemRgb lives in hg/cgilib, which has no tests directory, so this one test links # jkhgapcgi.a on top of the libraries the rest of this directory uses. Two runs, because the # last step of the rule reads hg.conf's alwaysItemRgb and a mirror may turn it off. bedItemRgbTest: mkdirs ${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/bedItemRgbTester bedItemRgbTester.c \ ${MYLIBDIR}/jkhgapcgi.a ${MYLIBS} $L echo "include ${HOME}/.hg.conf" > output/rgbOn.conf echo "include ${HOME}/.hg.conf" > output/rgbOff.conf echo "alwaysItemRgb=off" >> output/rgbOff.conf HGDB_CONF=output/rgbOn.conf ${BIN_DIR}/bedItemRgbTester > output/bedItemRgbTest HGDB_CONF=output/rgbOff.conf ${BIN_DIR}/bedItemRgbTester >> output/bedItemRgbTest diff expected/bedItemRgbTest output/bedItemRgbTest +hVarSubstHtmlTest: mkdirs + ${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/hVarSubstHtmlTester hVarSubstHtmlTester.c ${MYLIBS} $L + ${BIN_DIR}/hVarSubstHtmlTester > output/hVarSubstHtmlTest + diff expected/hVarSubstHtmlTest output/hVarSubstHtmlTest + sqlCheck: ${BIN_DIR}/sqlCheck mkdirs ${MAKE} -f sqlCheck.mk test BIN_DIR=${BIN_DIR} OUT_DIR=output clean: rm -rf *.o bin output *.tmp loader udcCache