09f26ed9a7dcc52b03b4d3e5b2f97c5177cd9334 max Mon Sep 21 06:00:40 2026 -0700 Drop the ${hgsid} trackDb variable; add session ids to links in the browser instead A description page's links can carry the session id without the page itself holding one. addHgsidToLinks() in utils.js walks the rendered page and appends hgsid to every that stays on this host and points into the same cgi-bin directory: a relative CGI link gets one, a static .html, a link to another host, a mailto and a plain #anchor do not, and a link that already names a session is left alone. hgc and hgTrackUi call it through a new jsAddHgsidToLinks(), and hgTracks.js calls it on the track description popup once the ajax content is in. A link written with a literal $hgsid is rewritten rather than skipped, so the description pages already deployed in the GenArk hubs work again. hVarSubst no longer knows about hgsid: it is out of the trackDb variable list, so hVarSubstTrackDbHtml is a hub-only pass again and needs no cart, and hVarSubstWithCart and webIncludeHelpFileSubst, which existed only to resolve it, are gone. The variable is taken out of the trackDb README and out of the twenty-odd description pages that used it. refs #38380 diff --git src/hg/js/hgTracks.js src/hg/js/hgTracks.js index 8f17edec7ec..6a99eec5e20 100644 --- src/hg/js/hgTracks.js +++ src/hg/js/hgTracks.js @@ -5754,30 +5754,34 @@ // Take html from hgTrackUi and put it up as a modal dialog. // make sure all links (e.g. help links) open up in a new window response = response.replace(/"+ cleanHtml +""); + // the description page inside carries no session id of its own, so add it to the + // links in it that stay on this server + addHgsidToLinks(document.getElementById('pop')); + appendNonceJsToPage(nonceJs); // Strategy for popups with js: // - jsFiles and CSS should not be included in html. Here they are shluped out. // - The resulting files ought to be loadable dynamically (with getScript()), // but this was not working nicely with the modal dialog // Therefore include files must be included with hgTracks CGI ! // - embedded js should not be in the popup box. // - Somethings should be in a popup.ready() function, and this is emulated below, // as soon as the cleanHtml is added // Since there are many possible popup cfg dialogs, the ready should be all inclusive. if ( ! popUp.trackDescriptionOnly ) { // If subtrack then vis rules differ var subtrack = tdbIsSubtrack(hgTracks.trackDb[popUp.trackName]) ? popUp.trackName :"";