9d9fff4aef9fd9a187839f72e49c3b5ad37ba34a max Tue Sep 15 05:48:47 2026 -0700 hgHubConnect: encode the hub URL into the Connect button's JS literal, refs #38353 The three sibling handlers nearby all pass it through javaScriptLiteralEncode; this one did not. diff --git src/hg/hgHubConnect/hgHubConnect.c src/hg/hgHubConnect/hgHubConnect.c index 1cb6a776c8c..48362310150 100644 --- src/hg/hgHubConnect/hgHubConnect.c +++ src/hg/hgHubConnect/hgHubConnect.c @@ -681,31 +681,32 @@ // if the name isn't currently loaded, we assume it's a hub if (!hDbExists(name)) { char buffer[512]; safef(buffer, sizeof buffer, "hub_%d_%s", id, name); name = cloneString(buffer); } safef(jsId, sizeof jsId, "hubConnectButton%d", count); printf("\n", jsId); jsOnEventByIdF("click", jsId, "document.connectHubForm.elements['hubUrl'].value= '%s';" "document.connectHubForm.elements['db'].value= '%s';" - "document.connectHubForm.submit();return true;", hubInfo->hubUrl,name); + "document.connectHubForm.submit();return true;", + javaScriptLiteralEncode(hubInfo->hubUrl), name); } ourCellEnd(); } else errAbort("cannot get id for hub with url %s\n", hubInfo->hubUrl); ourPrintCellLink(hubInfo->shortLabel, hubInfo->hubUrl); boolean hubHasNoError = isEmpty(hubInfo->errorMessage); if (hubHasNoError) { if (hubInfo->tableHasDescriptionField && !isEmpty(hubInfo->descriptionUrl)) ourPrintCellLink(hubInfo->longLabel, hubInfo->descriptionUrl); else