0ae2a6a36d7b4c77e8e7d7df2a1049f4412e7099
max
  Fri Sep 18 07:03:44 2026 -0700
hgHubConnect: let a mirror hand out its own API keys, and stop swallowing links to another host

#Preview2 week - bugs introduced now will need a build patch to fix
Two of the three problems QA found on #38323.

The link in the mirror-only Hub Upload message did not go anywhere. The tab
handler in hgHubConnect.js catches every hgHubConnect link with a hash and turns
it into a tab switch, and 'Go to Hub Upload on genome.ucsc.edu' has a hash that
names a tab on the mirror too, so the click just reopened the tab the reader was
already on. It now only intercepts links to the page itself.

The API key section was decoupled from storeUserFiles, but only for display: the
Generate and Revoke buttons are cartJson requests, and both the javascript that
sends them and the code in main() that routes them were still inside the
storeUserFiles gate. A site with showHubApiKey on and hubSpace off therefore drew
two dead buttons. The key functions move out of hgMyData.js into a new
hubApiKey.js that the Hub Development tab includes on its own, main() routes a
cartJson request when either setting is on, and the hubSpace file commands stay
registered only when hubSpace is actually running.

The request also goes to this host's hgHubConnect now rather than to the login
host. Keys live in the central database of the server that issues them, so a key
made on genome-euro belongs in genome-euro's table.

refs #38323

diff --git src/hg/js/hgHubConnect.js src/hg/js/hgHubConnect.js
index e5ed93ecf7a..2d3e0296a9a 100644
--- src/hg/js/hgHubConnect.js
+++ src/hg/js/hgHubConnect.js
@@ -78,30 +78,35 @@
 
   $("#tabs").tabs({
       active: localStorage.getItem("hubTab") !== null ? localStorage.getItem("hubTab") : 0,
       activate: function(event, ui) {
           localStorage.setItem("hubTab", ui.newTab.index());
       },
   });
   // activate the tab named by the current URL hash
   var initialIndex = tabIndexForHash(window.location.hash);
   if (initialIndex >= 0)
       $("#tabs").tabs("option", "active", initialIndex);
 
   // menubar links point to hgHubConnect#<tab>. When already on this page a same-page
   // hash link only scrolls; intercept and switch tabs instead.
   $(document).on("click", "a[href*='hgHubConnect'][href*='#']", function(ev) {
+      // only same-page links are tab switches. A mirror sends people to the hgHubConnect
+      // of the login host, and that hash names a tab here too, so without this check the
+      // link is swallowed and reopens the tab the reader is already looking at.
+      if (this.host !== window.location.host)
+          return;
       var index = tabIndexForHash(this.hash);
       if (index >= 0) {
           ev.preventDefault();
           $("#tabs").tabs("option", "active", index);
           // we didn't navigate, so close the hover menu holding this link
           var $menuParent = $(this).closest("li.menuparent");
           $menuParent.hideSuperfishUl();
           $menuParent.find("> button, > a").attr("aria-expanded", "false");
       }
   });
 
   $("#tabs").tabs().on("tabsactivate", function(event, ui) {
     const  newHash = ui.newTab.find("a").attr("href");
     if (newHash) {
       history.replaceState(null, null, newHash);