d898b4820087cccd79e240153bc310856bb89310
braney
Sat Sep 19 18:22:49 2026 -0700
hVarSubstHtmlTester: pin which variables a description page may use
A native description page has been through hgTrackDb already, which resolved
everything it could and deferred only ${hgsid}, so the render pass acts on that
one variable and only in braces: hgTrackDb collapses an escaped $$hgsid to a
literal $hgsid, and acting on the bare form here would expand the very thing
the author escaped.
A hub's page has never been substituted, so the whole hub list is resolved at
render time, and $hgsid is deliberately not on that list. A hub page is only
lightly sanitized -- an
with an http src survives -- so a page carrying
would hand the reader's session
id to the hub's own server, and a session id alone is enough to read and write
that cart. The page renders the same either way and the request goes to
somebody else's host, so nothing about this is visible here.
The test builds a cart by hand rather than opening one. That is not a
shortcut, it is the point: a cartless version of this test was written first,
and adding hgsid back to hubHtmlVars changed not one line of its output,
because the check that recognises a variable also asks whether this call can
resolve it, and with no cart it cannot. cartSessionId reads two fields, so a
struct built in the test is enough and no database is involved.
Watched to fail and then pass: with hgsid back on the hub list, both hub cases
come back with the session id substituted into the img src. Recorded as
sandbox-ab in utils/testRegistry.
refs #38283, refs #38391
diff --git src/hg/lib/tests/makefile src/hg/lib/tests/makefile
index 526d235e3c0..239a37ad450 100644
--- src/hg/lib/tests/makefile
+++ src/hg/lib/tests/makefile
@@ -1,127 +1,133 @@
kentSrc = ../../..
include ../../../inc/common.mk
L += ${MYSQLLIBS} -lm
MYLIBDIR = ../../../lib/${MACHTYPE}
MYLIBS = ${MYLIBDIR}/jkhgap.a ${MYLIBDIR}/jkweb.a
BIN_DIR = bin/${MACHTYPE}
all: ${BIN_DIR}/genePredTester \
${BIN_DIR}/trashDirTester \
${BIN_DIR}/mallocTopPadTester \
${BIN_DIR}/pslReaderTester \
${BIN_DIR}/quickLiftTester \
${BIN_DIR}/sessionDataTester \
${BIN_DIR}/trashDirTester \
# ${BIN_DIR}/annoGratorTester \
${BIN_DIR}/binTest \
${BIN_DIR}/customTrackTester \
${BIN_DIR}/hgvsTester \
${BIN_DIR}/sqlCheck
${BIN_DIR}/%: %.c ${MYLIBS}
@${MKDIR} ${BIN_DIR}
${CC} ${CC_PROG_OPTS} -o $@ $*.c ${MYLIBS} $L
#test: binTest spDbTest hdbTest genePredTest pslReaderTest annoGratorTest customTrackTest hgvsTest
-test: binTest quickLiftTest sessionDataTest trashDirTest mallocTopPadTest bedItemRgbTest spDbTest hdbTest genePredTest pslReaderTest customTrackTest hgvsTest
+test: binTest quickLiftTest sessionDataTest trashDirTest mallocTopPadTest bedItemRgbTest \
+ hVarSubstHtmlTest spDbTest hdbTest genePredTest pslReaderTest customTrackTest hgvsTest
rm -r output
echo tested all
mkdirs:
@${MKDIR} output ${BIN_DIR}
loaders:
ln -sf ${CGI_BIN}/loader .
spDbTest: ${BIN_DIR}/spDbTest mkdirs
${BIN_DIR}/spDbTest sp121210 Q9FFH7 > output/spDbTest
${BIN_DIR}/spDbTest sp121210 P29312 >> output/spDbTest
diff expected/spDbTest output/spDbTest
hdbTest: ${BIN_DIR}/hdbTest mkdirs
${BIN_DIR}/hdbTest > output/hdbTest
diff expected/hdbTest output/hdbTest
genePredTest: ${BIN_DIR}/genePredTester mkdirs
${MAKE} -f genePredTests.mk test
pslReaderTest: ${BIN_DIR}/pslReaderTester mkdirs
${MAKE} -f pslReaderTests.mk test
#annoGratorTest: ${BIN_DIR}/annoGratorTester mkdirs
# ${MAKE} -f annoGratorTests.mk test
customTrackTest: ${BIN_DIR}/customTrackTester loaders mkdirs
${MAKE} -f customTrackTests.mk test BIN_DIR=${BIN_DIR} OUT_DIR=output
hgvsTest: ${BIN_DIR}/hgvsTester mkdirs
${MAKE} -f hgvsTests.mk test
binTest: mkdirs ${BIN_DIR}/binTest
@./binTest.sh
quickLiftTest: ${BIN_DIR}/quickLiftTester mkdirs
${BIN_DIR}/quickLiftTester > output/quickLiftTest
diff expected/quickLiftTest output/quickLiftTest
sessionDataTest: ${BIN_DIR}/sessionDataTester mkdirs
${BIN_DIR}/sessionDataTester output/sessionData > output/sessionDataTest
diff expected/sessionDataTest output/sessionDataTest
# Three runs, because hgConfig caches the config it read, so one process can only answer for
# one spelling of sessionDataDir. The fixture is made here rather than in C: a directory, a
# symlink to it, and three confs naming the same place three ways. Each conf includes the
# developer's own so the database settings come along, and is mode 600 because hgConfig
# refuses a group-readable file whose name begins with a dot -- these do not, but the habit is
# worth keeping.
trashDirTest: ${BIN_DIR}/trashDirTester mkdirs
rm -rf output/sd
${MKDIR} output/sd/real/hgt
ln -s real output/sd/link
echo "include ${HOME}/.hg.conf" > output/sd/link.conf
echo "sessionDataDir=`pwd`/output/sd/link" >> output/sd/link.conf
echo "include ${HOME}/.hg.conf" > output/sd/real.conf
echo "sessionDataDir=`pwd`/output/sd/real" >> output/sd/real.conf
echo "include ${HOME}/.hg.conf" > output/sd/rel.conf
echo "sessionDataDir=output/sd/link" >> output/sd/rel.conf
HGDB_CONF=output/sd/link.conf ${BIN_DIR}/trashDirTester \
"the symlink, absolute" `pwd`/output/sd/link `pwd`/output/sd/real \
> output/trashDirTest
HGDB_CONF=output/sd/real.conf ${BIN_DIR}/trashDirTester \
"the resolved directory, absolute" `pwd`/output/sd/link `pwd`/output/sd/real \
>> output/trashDirTest
HGDB_CONF=output/sd/rel.conf ${BIN_DIR}/trashDirTester \
"the symlink, relative" `pwd`/output/sd/link `pwd`/output/sd/real \
>> output/trashDirTest
diff expected/trashDirTest output/trashDirTest
# Twice: once with the setting and once without, because the answer is the DIFFERENCE between
# them. A single run could pass on a library whose own default happened to be large.
mallocTopPadTest: ${BIN_DIR}/mallocTopPadTester mkdirs
echo "include ${HOME}/.hg.conf" > output/topPadOff.conf
echo "include ${HOME}/.hg.conf" > output/topPadOn.conf
echo "mallocTopPad=33554432" >> output/topPadOn.conf
HGDB_CONF=output/topPadOff.conf ${BIN_DIR}/mallocTopPadTester > output/mallocTopPadTest
HGDB_CONF=output/topPadOn.conf ${BIN_DIR}/mallocTopPadTester >> output/mallocTopPadTest
diff expected/mallocTopPadTest output/mallocTopPadTest
# bedItemRgb lives in hg/cgilib, which has no tests directory, so this one test links
# jkhgapcgi.a on top of the libraries the rest of this directory uses. Two runs, because the
# last step of the rule reads hg.conf's alwaysItemRgb and a mirror may turn it off.
bedItemRgbTest: mkdirs
${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/bedItemRgbTester bedItemRgbTester.c \
${MYLIBDIR}/jkhgapcgi.a ${MYLIBS} $L
echo "include ${HOME}/.hg.conf" > output/rgbOn.conf
echo "include ${HOME}/.hg.conf" > output/rgbOff.conf
echo "alwaysItemRgb=off" >> output/rgbOff.conf
HGDB_CONF=output/rgbOn.conf ${BIN_DIR}/bedItemRgbTester > output/bedItemRgbTest
HGDB_CONF=output/rgbOff.conf ${BIN_DIR}/bedItemRgbTester >> output/bedItemRgbTest
diff expected/bedItemRgbTest output/bedItemRgbTest
+hVarSubstHtmlTest: mkdirs
+ ${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/hVarSubstHtmlTester hVarSubstHtmlTester.c ${MYLIBS} $L
+ ${BIN_DIR}/hVarSubstHtmlTester > output/hVarSubstHtmlTest
+ diff expected/hVarSubstHtmlTest output/hVarSubstHtmlTest
+
sqlCheck: ${BIN_DIR}/sqlCheck mkdirs
${MAKE} -f sqlCheck.mk test BIN_DIR=${BIN_DIR} OUT_DIR=output
clean:
rm -rf *.o bin output *.tmp loader udcCache