09f26ed9a7dcc52b03b4d3e5b2f97c5177cd9334
max
Mon Sep 21 06:00:40 2026 -0700
Drop the ${hgsid} trackDb variable; add session ids to links in the browser instead
A description page's links can carry the session id without the page itself holding
one. addHgsidToLinks() in utils.js walks the rendered page and appends hgsid to every
<a href> that stays on this host and points into the same cgi-bin directory: a relative
CGI link gets one, a static .html, a link to another host, a mailto and a plain #anchor
do not, and a link that already names a session is left alone. hgc and hgTrackUi call
it through a new jsAddHgsidToLinks(), and hgTracks.js calls it on the track description
popup once the ajax content is in. A link written with a literal $hgsid is rewritten
rather than skipped, so the description pages already deployed in the GenArk hubs work
again.
hVarSubst no longer knows about hgsid: it is out of the trackDb variable list, so
hVarSubstTrackDbHtml is a hub-only pass again and needs no cart, and hVarSubstWithCart
and webIncludeHelpFileSubst, which existed only to resolve it, are gone. The variable
is taken out of the trackDb README and out of the twenty-odd description pages that
used it.
refs #38380
diff --git src/hg/lib/jsHelper.c src/hg/lib/jsHelper.c
index 6b3b5076c08..2c0210f244d 100644
--- src/hg/lib/jsHelper.c
+++ src/hg/lib/jsHelper.c
@@ -319,30 +319,45 @@
, stateString);
return loadFunction;
}
char *jsCheckAllOnClickHandler(char *idPrefix, boolean state)
/* Returns javascript for use as an onclick attribute value to check all/uncheck all
* all checkboxes with given idPrefix.
* state parameter determines whether to "check all" or "uncheck all" (TRUE means "check all"). */
{
static char buf[512];
jsIncludeFile("utils.js", NULL);
safef(buf, sizeof(buf), "setCheckBoxesWithPrefix(this, '%s', %s); return false", idPrefix, state ? "true" : "false");
return buf;
}
+void jsAddHgsidToLinks()
+/* Emit the javascript that gives every link on this page to one of our own CGIs the current
+ * session id. See addHgsidToLinks() in utils.js: a track description page comes from
+ * whoever wrote the track or the hub, so the session id cannot be substituted into it on
+ * the server without also handing it to an <img> that points somewhere else. */
+{
+static boolean done = FALSE;
+if (done)
+ return;
+done = TRUE;
+jsIncludeFile("utils.js", NULL);
+// jsInlineFinish() writes this at the end of the body, so the page is parsed by then
+jsInline("addHgsidToLinks(document);\n");
+}
+
/* cgiMakeCheckAllSubmitButton really belongs in cheapcgi.c, but that is compiled without access to jsHelper.h */
void cgiMakeCheckAllSubmitButton(char *name, char *value, char *id, char *idPrefix, boolean state)
/* Make submit button which uses javascript to apply check all or uncheck all to all
* checkboxes with given idPrefix.
* state parameter determines whether to "check all" or "uncheck all" (TRUE means "check all").
* id parameter may be NULL */
{
cgiMakeOnClickSubmitButton(jsCheckAllOnClickHandler(idPrefix, state), name, value);
}
char *stripRegEx(char *str, char *regEx, int flags)
{
/* Strip out text matching regEx from str.
flags is passed through to regcomp as the cflags argument.