cb99f0b11bdeee5dfa76064d38b6410da0f4a709
max
  Thu Sep 10 00:55:21 2026 -0700
Centralize CGI Content-Type printing in one cgiPrintContentType() helper

Around 90 places across the tree hand-rolled the CGI response header, each
with its own spelling: "Content-Type:" or "Content-type:", \n or \r\n, and
the terminating blank line written as part of the same string, as a separate
puts("\n") (which emits two newlines, so a stray blank line led the body) or
as printf("\r\n\r\n") (two blank lines).  A handful forgot the terminator
entirely and relied on a following header to supply it.

cgiPrintContentType() in lib/cheapcgi.c now writes the Content-Type line and
the blank line that ends the header.  Header lines are not ordered, so the
callers that also send Status, Set-Cookie, Content-Disposition, Content-Length
or X-Sendfile write those first and call this last to close the header; that
keeps it to a single helper rather than a print-the-line / end-the-header pair
that a caller can half-use.  cart.c's existing httpHeaders list already worked
this way.

Only the CGI response path is touched.  The dyStringPrintf("Content-type: ...")
calls that build outgoing HTTP *requests* (genomeSpace, oauthLogin, eapMetaSync,
edwWebAuthLogin, ga4ghToBed) are unrelated and left alone.

Also fills out the apiKey error message in botDelay.c to say where to create a
key and that keys are server-specific.

No behavior change on the wire beyond dropping those stray blank lines and
adding the missing newline after Retry-After.

diff --git src/hg/hubApi/blat.c src/hg/hubApi/blat.c
index 251a39a460e..8d00c1fed14 100644
--- src/hg/hubApi/blat.c
+++ src/hg/hubApi/blat.c
@@ -125,47 +125,47 @@
         subChar(seq->dna, 'u', 't');
         }
     }
 if (seqList != NULL && seqList->name[0] == 0)
     {
     freeMem(seqList->name);
     seqList->name = cloneString("YourSeq");
     }
 }
 
 static void writePslOutput(struct psl *pslList, struct blatType *bt)
 /* PSL text output path (output=psl). */
 {
 hPrintDisable();
 puts("X-Content-Type-Options: nosniff");
-puts("Content-Type:text/plain\n");
+cgiPrintContentType("text/plain");
 pslxWriteHead(stdout, bt->qType, bt->tType);
 struct psl *psl;
 int n = 0;
 for (psl = pslList; psl != NULL && n < maxItemsOutput; psl = psl->next, ++n)
     pslTabOut(psl, stdout);
 }
 
 static void writeLegacyJsonOutput(struct psl *pslList, char *db)
 /* Byte-for-byte the same JSON shape hgBlat?output=json emits: a top-level
  * object with "track":"blat", "genome", a "fields" header array, and "blat"
  * as an array of arrays (one row per PSL).
  * Triggered by format=hgblat or jsonOutputArrays=1. */
 {
 hPrintDisable();
 puts("X-Content-Type-Options: nosniff");
-puts("Content-Type:text/plain\n");
+cgiPrintContentType("text/plain");
 pslWriteAllJson(pslList, stdout, db, TRUE);
 }
 
 static void writePslAsObject(struct jsonWrite *jw, struct psl *psl)
 /* Write one PSL hit as a JSON object with named keys. */
 {
 int b;
 jsonWriteObjectStart(jw, NULL);
 jsonWriteNumber(jw, "matches", psl->match);
 jsonWriteNumber(jw, "misMatches", psl->misMatch);
 jsonWriteNumber(jw, "repMatches", psl->repMatch);
 jsonWriteNumber(jw, "nCount", psl->nCount);
 jsonWriteNumber(jw, "qNumInsert", psl->qNumInsert);
 jsonWriteNumber(jw, "qBaseInsert", psl->qBaseInsert);
 jsonWriteNumber(jw, "tNumInsert", psl->tNumInsert);