d898b4820087cccd79e240153bc310856bb89310 braney Sat Sep 19 18:22:49 2026 -0700 hVarSubstHtmlTester: pin which variables a description page may use A native description page has been through hgTrackDb already, which resolved everything it could and deferred only ${hgsid}, so the render pass acts on that one variable and only in braces: hgTrackDb collapses an escaped $$hgsid to a literal $hgsid, and acting on the bare form here would expand the very thing the author escaped. A hub's page has never been substituted, so the whole hub list is resolved at render time, and $hgsid is deliberately not on that list. A hub page is only lightly sanitized -- an with an http src survives -- so a page carrying would hand the reader's session id to the hub's own server, and a session id alone is enough to read and write that cart. The page renders the same either way and the request goes to somebody else's host, so nothing about this is visible here. The test builds a cart by hand rather than opening one. That is not a shortcut, it is the point: a cartless version of this test was written first, and adding hgsid back to hubHtmlVars changed not one line of its output, because the check that recognises a variable also asks whether this call can resolve it, and with no cart it cannot. cartSessionId reads two fields, so a struct built in the test is enough and no database is involved. Watched to fail and then pass: with hgsid back on the hub list, both hub cases come back with the session id substituted into the img src. Recorded as sandbox-ab in utils/testRegistry. refs #38283, refs #38391 diff --git src/hg/lib/tests/expected/hVarSubstHtmlTest src/hg/lib/tests/expected/hVarSubstHtmlTest new file mode 100644 index 00000000000..fe8b033df44 --- /dev/null +++ src/hg/lib/tests/expected/hVarSubstHtmlTest @@ -0,0 +1,24 @@ +a hub's description page + $db resolves

assembly $db

->

assembly hg38

+ ${db} in braces too

assembly ${db}

->

assembly hg38

+ $$db stays a dollar

$$db

->

$db

+ $hgsid is NOT a variable -> + ${hgsid} is NOT a variable -> + a price is not a variable

costs $5 million

->

costs $5 million

+ +a native description page + ${hgsid} is acted on go -> go + $hgsid is left alone go -> go + $db was done by hgTrackDb

assembly $db

->

assembly $db

+ a price is not a variable

costs $5 million

->

costs $5 million

+ +with no cart at all + hub page, ${hgsid} -> + native page, ${hgsid} go -> go + hub page, $db

assembly $db

->

assembly hg38

+ +nothing to substitute + no dollar at all

plain

->

plain

+ empty page -> + a NULL track returned, no crash +