beb596d6144e0deb9ce96c5955c71e6d5f4eaec9 braney Sat Sep 26 13:01:02 2026 -0700 trackHub: add an hg.conf switch for hub description page handling, refs #38126 hubHtmlSanitizeOn() in trackHub.c reads the hg.conf setting hubHtmlSanitize, default off, and the description page code in lib and cgilib asks it. With the setting off, that code behaves as it did in v503. hubCheck follows the same setting. diff --git src/hg/cgilib/cartJson.c src/hg/cgilib/cartJson.c index 42da4c3c5cc..b9d48db6b75 100644 --- src/hg/cgilib/cartJson.c +++ src/hg/cgilib/cartJson.c @@ -710,33 +710,38 @@ { char *htmlPath = hHtmlPath(db); char *htmlString = NULL; if (htmlPath != NULL) { if (fileExists(htmlPath)) readInGulp(htmlPath, &htmlString, NULL); else if (startsWith("http://" , htmlPath) || startsWith("https://", htmlPath) || startsWith("ftp://" , htmlPath)) { struct lineFile *lf = udcWrapShortLineFile(htmlPath, NULL, 256*1024); char *fetched = lineFileReadAll(lf); lineFileClose(&lf); /* This one came in over the network from a hub, so print only what we allow. */ + if (hubHtmlSanitizeOn()) + { htmlString = htmlSanitize(fetched); freeMem(fetched); } + else + htmlString = fetched; + } } return htmlString; } static void getAssemblyInfo(struct cartJson *cj, struct hash *paramHash) /* Return useful things from dbDb (or track hub) and assembly description html (possibly NULL). * If db param is NULL, use db from cart. */ { char *db = cartJsonOptionalParam(paramHash, "db"); if (db == NULL) db = cartString(cj->cart, "db"); jsonWriteString(cj->jw, "db", db); jsonWriteString(cj->jw, "commonName", hGenome(db)); jsonWriteString(cj->jw, "scientificName", hScientificName(db)); jsonWriteString(cj->jw, "dbLabel", hFreezeDate(db));