3c7dea1af68a9671ba48c550be453845827e115d
hiram
  Wed Sep 16 16:44:17 2026 -0700
gracefully manage bad response from login status refs #38365

diff --git src/hg/js/liftRequest.js src/hg/js/liftRequest.js
index c08b55d24ef..061afc2e442 100644
--- src/hg/js/liftRequest.js
+++ src/hg/js/liftRequest.js
@@ -176,58 +176,95 @@
 function validateEmail(checkEmail) {
     // Require at least one dot in domain
     var validEmail = /^[a-zA-Z0-9.!#$%&'*+/=?^_`{|}~-]+@[a-zA-Z0-9-]+(?:\.[a-zA-Z0-9-]+)+$/;
 
     if (!validEmail.test(checkEmail)) {
         alert("You have entered an invalid email address !");
         return false;
     }
     return true;
 }
 
 function checkLoginStatus() {
     // Check user login status and update UI accordingly
     const returnTo = encodeURIComponent(window.location.href);
     fetch(`/cgi-bin/hubApi/liftOver/loginStatus?returnTo=${returnTo}`)
-        .then(response => response.json())
+        .then(response => {
+            if (!response.ok) {
+                throw new Error("loginStatus request failed: " + response.status);
+            }
+            return response.json();
+        })
         .then(data => {
             updateUIForLoginStatus(data);
         })
         .catch(error => {
             console.log('Login status check failed:', error);
-            // Assume not logged in on error
-            updateUIForLoginStatus({userName: null});
+            // Status could not be determined (blocked, down, bad response, etc).
+            // Do not guess; show a neutral unavailable state instead.
+            updateUIForLoginStatus(null);
         });
 }
 
 function updateUIForLoginStatus(loginData) {
     const emailInput = document.getElementById('emailInput');
     const submitBtn = document.getElementById('submitBtn');
 
     // Create or update login banner
     let loginBanner = document.getElementById('loginBanner');
     if (!loginBanner) {
         loginBanner = document.createElement('div');
         loginBanner.id = 'loginBanner';
         loginBanner.style.cssText = 'background-color: #f0f8ff; padding: 10px; margin-bottom: 15px; border-radius: 5px; border: 1px solid #ddd;';
 
         // Insert after the h1 title
         const formContainer = document.getElementById('formContainer');
         const title = formContainer.querySelector('h1');
         title.parentNode.insertBefore(loginBanner, title.nextSibling);
     }
 
+    // loginData is null when the loginStatus check failed or was blocked;
+    // treat missing loginUrl/signupUrl the same way rather than building
+    // links out of undefined values.
+    var statusUnavailable = !loginData ||
+        (!loginData.userName && (!loginData.loginUrl || !loginData.signupUrl));
+
+    if (statusUnavailable) {
+        loginBanner.textContent =
+            'Unable to verify sign-in status right now. Please reload the page' +
+            ' or try again later.';
+
+        emailInput.value = '';
+        emailInput.placeholder = 'Sign-in status unavailable';
+        emailInput.disabled = true;
+        emailInput.style.backgroundColor = '#f0f0f0';
+
+        const emailForm = document.getElementById('emailForm');
+        const description = emailForm.querySelector('.description');
+        if (description) {
+            description.textContent =
+                'Sign-in status could not be verified, so requests cannot be' +
+                ' submitted right now.';
+        }
+
+        submitBtn.disabled = true;
+        submitBtn.value = 'Unavailable';
+        submitBtn.style.backgroundColor = '#ddd';
+        submitBtn.style.cursor = 'not-allowed';
+        return;
+    }
+
     if (loginData.userName) {
         // User is logged in
         var displayName = loginData.realName || loginData.userName;
         loginBanner.innerHTML = '<p>Welcome, <strong>' + displayName + '</strong> | ' +
             '<a href="' + loginData.logoutUrl + '">Sign out</a></p>';
 
         // Prefill and lock email field
         emailInput.value = loginData.email || '';
         emailInput.readOnly = true;
         emailInput.style.backgroundColor = '#f5f5f5';
         emailInput.style.cursor = 'not-allowed';
 
         // Update email form description
         const emailForm = document.getElementById('emailForm');
         const description = emailForm.querySelector('.description');