435d98f2883cd5b7e355c5df0695fa0ce092bc88
max
  Mon Sep 21 05:56:51 2026 -0700
botDelay: the invalid-apiKey message says nothing about where a key is valid, refs #38323

The message had two variants, one for syncHubApiKeys on and one for off,
differing only in whether they told the user that apiKeys are server-
specific.  Keys are going to be synced across the mirrors, so the whole
distinction is about to be wrong in one direction or the other.  Dropped
it: one message, no claim either way, and the link to create a key still
points at the server the request came in on.

diff --git src/hg/lib/botDelay.c src/hg/lib/botDelay.c
index 937fb3ecb62..1b5f2162b6b 100644
--- src/hg/lib/botDelay.c
+++ src/hg/lib/botDelay.c
@@ -221,50 +221,38 @@
         char *apiKey = cgiOptionalString("apiKey");
         if (apiKey)
             {
             // Here we do a mysql query before the bottleneck is complete. 
             // And this is better than handling the request without bottleneck
             // The connection is closed right away, so if the bottleneck leads to a long sleep, it won't tie up
             // the MariaDB server. The cost of opening a connection is less than 1msec.
             struct sqlConnection *conn = hConnectCentralNoCache();
             char *userName = hubSpaceUserNameForApiKey(conn, apiKey);
             sqlDisconnect(&conn);
 
             if (userName)
                 safef(botCheckString, 256, "apiKey%s %f", apiKey, fraction);
             else
                 {
-                // Point at this server, whichever one it is, rather than at a hardcoded
-                // host: the key has to be created where it is used, unless the mirrors
-                // are syncing keys between themselves.
+                // Point at this server, whichever one it is, rather than at a hardcoded host
                 char keyUrl[1024];
                 safef(keyUrl, sizeof(keyUrl), "http%s://%s/cgi-bin/hgHubConnect#hubDeveloper",
                         cgiAppendSForHttps(), cgiServerNamePort());
-                if (cfgOptionBooleanDefault("syncHubApiKeys", FALSE))
-                    // hgHubConnect copies a new or revoked key to the other geo mirror nodes,
-                    // so a key made on any of them is valid here
                 hUserAbort("Invalid apiKey provided on URL. "
                         "Make sure that the apiKey is valid, "
-                            "check %s to create one or check this key. An apiKey created on any "
-                            "UCSC genome browser mirror works on all of them. "
+                        "check %s to create one or check this key. "
                         "If you have problems with the apiKey, contact us.", keyUrl);
-                else
-                    hUserAbort("Invalid apiKey provided on URL. "
-                            "Make sure that the apiKey is valid, "
-                            "check %s to create one or check this key. Note that apiKeys are "
-                            "server-specific, so the key must be created on the same server where "
-                            "it is used. If you have problems with the apiKey, contact us.", keyUrl);
                 }
             }
         else
             {
             if (isValidHguid(cookieUserId))
                 safef(botCheckString, 256, "uid%s %f", cookieUserId, fraction);
             else
                 {
                 // The following happens very rarely on sites like our RR that use the cloudflare captcha,
                 // as all requests (except hgLogin, hgRenderTracks) should come in with a cookie user ID
                 char *hgsid = cgiOptionalString("hgsid");
                 // For now, we do not check the hgsid against the MariaDb table, only check if the string looks OK
                 if (hgsid && isValidHgsidForEarlyBotCheck(hgsid))
                     safef(botCheckString, 256, "sid%s %f", hgsid, fraction);
                 else