03bd4721a68ec74cab51164ff2d4b216cd6fe9b0
max
  Tue Sep 15 05:49:00 2026 -0700
trackDb README and comments: $hgsid is for native description pages only, refs #38353

The README still described $hgsid as a hub-page variable that is empty in native trackDb;
both halves of that are now the other way round.  The three call sites of
hVarSubstTrackDbHtml that still said a hub page is the only reason it exists say what the
call does now.

diff --git src/hg/makeDb/trackDb/README src/hg/makeDb/trackDb/README
index c256d9bf542..66568dd11ef 100644
--- src/hg/makeDb/trackDb/README
+++ src/hg/makeDb/trackDb/README
@@ -64,35 +64,38 @@
                chain or chainNet html page: 'Chains scoring below a minimum
                score of "${chainMinScore}" were discarded'.
      ${chainLinearGap} - value for the -linearGap matrix used with axtChain
                (e.g. loose, medium). Gets substituted into the chain or
                chainNet html page.
      ${downloadsServer} - the value of the hg.conf downloads.server variable, or
                          hgdownload.soe.ucsc.edu if not set.
      ${track} - the track's own name, as hgTrackUi's g= parameter needs it. For
                a hub track that includes the hub_<id>_ prefix.
      ${parentTrack} - the name of the container the track sits in, a superTrack
                or a composite, in the same form as ${track}. Views are skipped,
                since a view has no description page of its own. For a track that
                is not in a container this is the same as ${track}. Useful for
                linking a subtrack's description page back to its container, e.g.
                <a href="hgTrackUi?db=${db}&amp;g=${parentTrack}">.
-     ${hgsid} - the current session id. Only a CGI has a cart to take this
-               from. Native trackDb html is substituted once by hgTrackDb when
-               it loads trackDb, and that happens without a cart, so ${hgsid}
-               is empty there. It is meant for hub description pages, which are
-               substituted at render time by hgc and hgTrackUi instead.
+     ${hgsid} - the current session id, in a native trackDb description page
+               only. hgTrackDb has no cart when it loads trackDb, so it leaves
+               the reference alone and hgc and hgTrackUi resolve it when they
+               render the page. It is not available in a hub's description
+               page: a hub is written by someone else, its html is only lightly
+               sanitized, and a session id in a hub page could be sent to the
+               hub's own server by something as ordinary as an <img> tag.
+               A session id is enough on its own to read and write that cart.
 In addition, if there is an otherDb field set in the .ra file, these
 variables are available:
      ${o_ORGANISM} - all upper case other organism, like 'MOUSE'
      ${o_Organism} - initial capped other organism, like 'Mouse'
      ${o_organism} - all lower case other organism, like 'mouse'
      ${o_db} - other database (like mm3, hg15, etc.)
      ${o_date} - freeze date of underlying other assembly
 
 Any other ra fields may be referenced as a variable.
 
 Always write the braces.  The bare form $name also works, terminated by a
 character other than [0-9A-Za-Z_], and older pages use it, but do not write it
 in anything new and do not document it.  Inside braces any character is allowed
 up to the closing brace, so ${name} leaves room for structured variable names
 later, something $name cannot express.  It also settles what happens when a