09f26ed9a7dcc52b03b4d3e5b2f97c5177cd9334 max Mon Sep 21 06:00:40 2026 -0700 Drop the ${hgsid} trackDb variable; add session ids to links in the browser instead A description page's links can carry the session id without the page itself holding one. addHgsidToLinks() in utils.js walks the rendered page and appends hgsid to every that stays on this host and points into the same cgi-bin directory: a relative CGI link gets one, a static .html, a link to another host, a mailto and a plain #anchor do not, and a link that already names a session is left alone. hgc and hgTrackUi call it through a new jsAddHgsidToLinks(), and hgTracks.js calls it on the track description popup once the ajax content is in. A link written with a literal $hgsid is rewritten rather than skipped, so the description pages already deployed in the GenArk hubs work again. hVarSubst no longer knows about hgsid: it is out of the trackDb variable list, so hVarSubstTrackDbHtml is a hub-only pass again and needs no cart, and hVarSubstWithCart and webIncludeHelpFileSubst, which existed only to resolve it, are gone. The variable is taken out of the trackDb README and out of the twenty-odd description pages that used it. refs #38380 diff --git src/hg/makeDb/trackDb/README src/hg/makeDb/trackDb/README index 66568dd11ef..32c80daf026 100644 --- src/hg/makeDb/trackDb/README +++ src/hg/makeDb/trackDb/README @@ -64,38 +64,41 @@ chain or chainNet html page: 'Chains scoring below a minimum score of "${chainMinScore}" were discarded'. ${chainLinearGap} - value for the -linearGap matrix used with axtChain (e.g. loose, medium). Gets substituted into the chain or chainNet html page. ${downloadsServer} - the value of the hg.conf downloads.server variable, or hgdownload.soe.ucsc.edu if not set. ${track} - the track's own name, as hgTrackUi's g= parameter needs it. For a hub track that includes the hub__ prefix. ${parentTrack} - the name of the container the track sits in, a superTrack or a composite, in the same form as ${track}. Views are skipped, since a view has no description page of its own. For a track that is not in a container this is the same as ${track}. Useful for linking a subtrack's description page back to its container, e.g. . - ${hgsid} - the current session id, in a native trackDb description page - only. hgTrackDb has no cart when it loads trackDb, so it leaves - the reference alone and hgc and hgTrackUi resolve it when they - render the page. It is not available in a hub's description - page: a hub is written by someone else, its html is only lightly - sanitized, and a session id in a hub page could be sent to the - hub's own server by something as ordinary as an tag. - A session id is enough on its own to read and write that cart. + +There is no variable for the session id, in a native page or a hub's. A +description page does not need one: a link in it that stays on this server has +the session id added by JavaScript in the browser, addHgsidToLinks() in +utils.js, so keeps the +reader in their own session. Substituting a session id into the page itself +would put it somewhere it can leak, since a description page is often written +by someone else and its html is only lightly sanitized: an tag pointing +at an outside address is enough to send the id to that server, and a session id +alone is enough to read and write that cart. + In addition, if there is an otherDb field set in the .ra file, these variables are available: ${o_ORGANISM} - all upper case other organism, like 'MOUSE' ${o_Organism} - initial capped other organism, like 'Mouse' ${o_organism} - all lower case other organism, like 'mouse' ${o_db} - other database (like mm3, hg15, etc.) ${o_date} - freeze date of underlying other assembly Any other ra fields may be referenced as a variable. Always write the braces. The bare form $name also works, terminated by a character other than [0-9A-Za-Z_], and older pages use it, but do not write it in anything new and do not document it. Inside braces any character is allowed up to the closing brace, so ${name} leaves room for structured variable names later, something $name cannot express. It also settles what happens when a