cb99f0b11bdeee5dfa76064d38b6410da0f4a709
max
  Thu Sep 10 00:55:21 2026 -0700
Centralize CGI Content-Type printing in one cgiPrintContentType() helper

Around 90 places across the tree hand-rolled the CGI response header, each
with its own spelling: "Content-Type:" or "Content-type:", \n or \r\n, and
the terminating blank line written as part of the same string, as a separate
puts("\n") (which emits two newlines, so a stray blank line led the body) or
as printf("\r\n\r\n") (two blank lines).  A handful forgot the terminator
entirely and relied on a following header to supply it.

cgiPrintContentType() in lib/cheapcgi.c now writes the Content-Type line and
the blank line that ends the header.  Header lines are not ordered, so the
callers that also send Status, Set-Cookie, Content-Disposition, Content-Length
or X-Sendfile write those first and call this last to close the header; that
keeps it to a single helper rather than a print-the-line / end-the-header pair
that a caller can half-use.  cart.c's existing httpHeaders list already worked
this way.

Only the CGI response path is touched.  The dyStringPrintf("Content-type: ...")
calls that build outgoing HTTP *requests* (genomeSpace, oauthLogin, eapMetaSync,
edwWebAuthLogin, ga4ghToBed) are unrelated and left alone.

Also fills out the apiKey error message in botDelay.c to say where to create a
key and that keys are server-specific.

No behavior change on the wire beyond dropping those stray blank lines and
adding the missing newline after Retry-After.

diff --git src/hg/useCount/useCount.c src/hg/useCount/useCount.c
index 295a18ecf8d..9401520f8a0 100644
--- src/hg/useCount/useCount.c
+++ src/hg/useCount/useCount.c
@@ -21,31 +21,31 @@
 char *remoteAddr = getenv("REMOTE_ADDR");
 char *userAgent = getenv("HTTP_USER_AGENT");
 char *version = cgiUsualString("version", "unknown");
 if (remoteAddr == NULL)
     remoteAddr = "unknown";
 if (userAgent == NULL)
     userAgent = "unknown";
 /* protect against huge strings coming in from outside */
 char safeAgent[255];
 snprintf(safeAgent, sizeof(safeAgent), "%s", userAgent);
 char safeAddr[255];
 snprintf(safeAddr, sizeof(safeAddr), "%s", remoteAddr);
 char safeVersion[255];
 snprintf(safeVersion, sizeof(safeVersion), "%s", version);
 
-printf("Content-Type:text/html\n\n\n");
+cgiPrintContentType("text/html");
 printf("<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 3.2//EN\">");
 printf("<HTML><HEAD>\n%s",getCspMetaHeader());
 
 struct sqlConnection *conn = hConnectCentral();
 if (conn)
     {
     char query[1024];
     if (sqlTableExists(conn, useCount))
 	{
 	sqlSafef(query, sizeof(query), "INSERT %s VALUES(0,\"%s\",\"%s\",now(),\"%s\")",
             useCount, safeAgent, safeAddr, safeVersion);
         sqlUpdate(conn,query);
 	count = sqlLastAutoId(conn);
 	sqlSafef(query, sizeof(query), "SELECT dateTime FROM %s WHERE count=%d",
 	    useCount, count);