7b3bd7a453e354dc0d4003bc7c65b073866f16f4 braney Tue Sep 29 13:35:06 2026 -0700 hgGateway: read a hub assembly's description the way other hub pages are read, refs #38430 diff --git src/hg/hgGateway/hgGateway.c src/hg/hgGateway/hgGateway.c index a0d73f49c51..83b9bc3e546 100644 --- src/hg/hgGateway/hgGateway.c +++ src/hg/hgGateway/hgGateway.c @@ -15,57 +15,65 @@ #include "cheapcgi.h" #include "errCatch.h" #include "googleAnalytics.h" #include "hCommon.h" #include "hgConfig.h" #include "hdb.h" #include "htmshell.h" #include "hubConnect.h" #include "hui.h" #include "jsHelper.h" #include "jsonParse.h" #include "obscure.h" // for readInGulp #include "regexHelper.h" #include "suggest.h" #include "trackHub.h" +#include "htmlSanitize.h" #include "web.h" #include "botDelay.h" #include "genark.h" #include "assemblyList.h" #include /* Global Variables */ struct cart *cart = NULL; /* CGI and other variables */ struct hash *oldVars = NULL; /* Old contents of cart before it was updated by CGI */ static boolean issueBotWarning = FALSE; static int measureTiming = 0; static long enteredMainTime = 0; #define SEARCH_TERM "hggw_term" static char *maybeGetDescriptionText(char *db) /* Slurp the description.html file for db into a string (if possible, don't die if * we can't read it) and return it. */ { struct errCatch *errCatch = errCatchNew(); char *descText = NULL; if (errCatchStart(errCatch)) { char *htmlPath = hHtmlPath(db); if (isNotEmpty(htmlPath)) descText = udcFileReadAll(htmlPath, NULL, 0, NULL); + /* A hub's page gets the same treatment here as everywhere else we show one. */ + if (descText != NULL && trackHubDatabase(db) && hubHtmlSanitizeOn()) + { + char *clean = htmlSanitize(descText); + freeMem(descText); + descText = clean; + } } errCatchEnd(errCatch); // Just ignore errors for now. return descText; } static int trackHubCountAssemblies(struct trackHub *hub) /* Return the number of hub's genomes that are hub assemblies, i.e. that have a twoBitPath. */ { int count = 0; struct trackHubGenome *genome; for (genome = hub->genomeList; genome != NULL; genome = genome->next) { if (isNotEmpty(genome->twoBitPath)) count++;