beb596d6144e0deb9ce96c5955c71e6d5f4eaec9
braney
  Sat Sep 26 13:01:02 2026 -0700
trackHub: add an hg.conf switch for hub description page handling, refs #38126

hubHtmlSanitizeOn() in trackHub.c reads the hg.conf setting hubHtmlSanitize,
default off, and the description page code in lib and cgilib asks it.  With
the setting off, that code behaves as it did in v503.  hubCheck follows the
same setting.

diff --git src/hg/lib/customFactory.c src/hg/lib/customFactory.c
index d873051a22c..0d06b18d575 100644
--- src/hg/lib/customFactory.c
+++ src/hg/lib/customFactory.c
@@ -3912,33 +3912,38 @@
 	    {
 	    char *newUrl = NULL;
 	    int newSd = 0;
 	    if (netSkipHttpHeaderLinesHandlingRedirect(sd, val, &newSd, &newUrl))
 		/* redirect can modify the url */
 		{
 		if (newUrl)
 		    {
 		    freeMem(newUrl);
 		    sd = newSd;
 		    }
 		ds = netSlurpFile(sd);
 		close(sd);
 		char *fetched = dyStringCannibalize(&ds);
 		/* This came in over the network, so keep only what we allow. */
+		if (hubHtmlSanitizeOn())
+		    {
 		    track->tdb->html = htmlSanitize(fetched);
 		    freeMem(fetched);
 		    }
+		else
+		    track->tdb->html = fetched;
+		}
 	    }
 	}
     errCatchEnd(errCatch);
     if (errCatch->gotError)
 	warn("%s", errCatch->message->string);
     errCatchFree(&errCatch);
     }
 
 tdb->url = hashFindVal(hash, "url");
 
 if ((val = hashFindVal(hash, "visibility")) != NULL)
     {
     if (isdigit(val[0]))
 	{
 	tdb->visibility = atoi(val);