9d9fff4aef9fd9a187839f72e49c3b5ad37ba34a
max
  Tue Sep 15 05:48:47 2026 -0700
hgHubConnect: encode the hub URL into the Connect button's JS literal, refs #38353

The three sibling handlers nearby all pass it through javaScriptLiteralEncode; this one did
not.

diff --git src/hg/hgHubConnect/hgHubConnect.c src/hg/hgHubConnect/hgHubConnect.c
index 1cb6a776c8c..48362310150 100644
--- src/hg/hgHubConnect/hgHubConnect.c
+++ src/hg/hgHubConnect/hgHubConnect.c
@@ -681,31 +681,32 @@
 
         // if the name isn't currently loaded, we assume it's a hub
         if (!hDbExists(name))
             {
             char buffer[512];
             safef(buffer, sizeof buffer, "hub_%d_%s",  id, name);
             name = cloneString(buffer);
             }
 
         safef(jsId, sizeof jsId, "hubConnectButton%d", count);
         printf("<input name=\"hubConnectButton\" id='%s' "
             "class=\"hubButton\" type=\"button\" value=\"Connect\">\n", jsId);
         jsOnEventByIdF("click", jsId, 
             "document.connectHubForm.elements['hubUrl'].value= '%s';"
             "document.connectHubForm.elements['db'].value= '%s';"
-            "document.connectHubForm.submit();return true;", hubInfo->hubUrl,name);
+            "document.connectHubForm.submit();return true;",
+            javaScriptLiteralEncode(hubInfo->hubUrl), name);
         }
 
     ourCellEnd();
     }
 else
     errAbort("cannot get id for hub with url %s\n", hubInfo->hubUrl);
 
 ourPrintCellLink(hubInfo->shortLabel, hubInfo->hubUrl);
 
 boolean hubHasNoError = isEmpty(hubInfo->errorMessage);
 if (hubHasNoError)
     {
     if (hubInfo->tableHasDescriptionField && !isEmpty(hubInfo->descriptionUrl))
         ourPrintCellLink(hubInfo->longLabel, hubInfo->descriptionUrl);
     else