cb99f0b11bdeee5dfa76064d38b6410da0f4a709
max
  Thu Sep 10 00:55:21 2026 -0700
Centralize CGI Content-Type printing in one cgiPrintContentType() helper

Around 90 places across the tree hand-rolled the CGI response header, each
with its own spelling: "Content-Type:" or "Content-type:", \n or \r\n, and
the terminating blank line written as part of the same string, as a separate
puts("\n") (which emits two newlines, so a stray blank line led the body) or
as printf("\r\n\r\n") (two blank lines).  A handful forgot the terminator
entirely and relied on a following header to supply it.

cgiPrintContentType() in lib/cheapcgi.c now writes the Content-Type line and
the blank line that ends the header.  Header lines are not ordered, so the
callers that also send Status, Set-Cookie, Content-Disposition, Content-Length
or X-Sendfile write those first and call this last to close the header; that
keeps it to a single helper rather than a print-the-line / end-the-header pair
that a caller can half-use.  cart.c's existing httpHeaders list already worked
this way.

Only the CGI response path is touched.  The dyStringPrintf("Content-type: ...")
calls that build outgoing HTTP *requests* (genomeSpace, oauthLogin, eapMetaSync,
edwWebAuthLogin, ga4ghToBed) are unrelated and left alone.

Also fills out the apiKey error message in botDelay.c to say where to create a
key and that keys are server-specific.

No behavior change on the wire beyond dropping those stray blank lines and
adding the missing newline after Retry-After.

diff --git src/hg/useCount/useCount.c src/hg/useCount/useCount.c
index 295a18ecf8d..9401520f8a0 100644
--- src/hg/useCount/useCount.c
+++ src/hg/useCount/useCount.c
@@ -1,64 +1,64 @@
 /* useCount - a simple CGI that merely counts its references. */
 
 /* Copyright (C) 2013 The Regents of the University of California 
  * See kent/LICENSE or http://genome.ucsc.edu/license/ for licensing information. */
 #include "common.h"
 #include "jksql.h"
 #include "cheapcgi.h"
 #include "htmshell.h"
 #include "hdb.h"
 
 
 /* table to use for counting in hgcentral */
 static char useCount[] = "useCount";
 
 int main(int argc, char *argv[])
 {
 int count = 0;
 cgiSpoof(&argc, argv);
 
 char dateTime[256];
 char *remoteAddr = getenv("REMOTE_ADDR");
 char *userAgent = getenv("HTTP_USER_AGENT");
 char *version = cgiUsualString("version", "unknown");
 if (remoteAddr == NULL)
     remoteAddr = "unknown";
 if (userAgent == NULL)
     userAgent = "unknown";
 /* protect against huge strings coming in from outside */
 char safeAgent[255];
 snprintf(safeAgent, sizeof(safeAgent), "%s", userAgent);
 char safeAddr[255];
 snprintf(safeAddr, sizeof(safeAddr), "%s", remoteAddr);
 char safeVersion[255];
 snprintf(safeVersion, sizeof(safeVersion), "%s", version);
 
-printf("Content-Type:text/html\n\n\n");
+cgiPrintContentType("text/html");
 printf("<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 3.2//EN\">");
 printf("<HTML><HEAD>\n%s",getCspMetaHeader());
 
 struct sqlConnection *conn = hConnectCentral();
 if (conn)
     {
     char query[1024];
     if (sqlTableExists(conn, useCount))
 	{
 	sqlSafef(query, sizeof(query), "INSERT %s VALUES(0,\"%s\",\"%s\",now(),\"%s\")",
             useCount, safeAgent, safeAddr, safeVersion);
         sqlUpdate(conn,query);
 	count = sqlLastAutoId(conn);
 	sqlSafef(query, sizeof(query), "SELECT dateTime FROM %s WHERE count=%d",
 	    useCount, count);
 	(void) sqlQuickQuery(conn, query, dateTime, sizeof(dateTime));
 	}
     else
 	{
 	printf("ERROR: can not find table '%s'<BR>\n", useCount);
 	}
     hDisconnectCentral(&conn);
     }
 
 printf("count: %d, date: %s<BR>\n", count, dateTime);
 printf("</HEAD></HTML>\n");
 return 0;
 }