beb596d6144e0deb9ce96c5955c71e6d5f4eaec9
braney
  Sat Sep 26 13:01:02 2026 -0700
trackHub: add an hg.conf switch for hub description page handling, refs #38126

hubHtmlSanitizeOn() in trackHub.c reads the hg.conf setting hubHtmlSanitize,
default off, and the description page code in lib and cgilib asks it.  With
the setting off, that code behaves as it did in v503.  hubCheck follows the
same setting.

diff --git src/hg/lib/customTrack.c src/hg/lib/customTrack.c
index 1bcbe9523a2..37eab85aa64 100644
--- src/hg/lib/customTrack.c
+++ src/hg/lib/customTrack.c
@@ -3,30 +3,31 @@
 
 /* Copyright (C) 2014 The Regents of the University of California 
  * See kent/LICENSE or http://genome.ucsc.edu/license/ for licensing information. */
 
 #include "common.h"
 #include "hash.h"
 #include "obscure.h"
 #include "memalloc.h"
 #include "portable.h"
 #include "errAbort.h"
 #include "errCatch.h"
 #include "linefile.h"
 #include "sqlList.h"
 #include "jksql.h"
 #include "htmlSanitize.h"
+#include "trackHub.h"
 #include "customTrack.h"
 #include "myVariants.h"
 #include "ctgPos.h"
 #include "psl.h"
 #include "gff.h"
 #include "genePred.h"
 #include "net.h"
 #include "hdb.h"
 #include "hui.h"
 #include "cheapcgi.h"
 #include "wiggle.h"
 #include "hgConfig.h"
 #include "customFactory.h"
 #include "trashDir.h"
 #include "jsHelper.h"
@@ -866,31 +867,31 @@
         {
         /* unreadable file */
         struct dyString *ds = dyStringNew(0);
         dyStringPrintf(ds, "Can't read doc file: %s", docFileName);
         err = dyStringCannibalize(&ds);
         customText = NULL;
         }
     }
 else
     html = cartUsualString(cart, CT_CUSTOM_DOC_TEXT_VAR, "");
 html = cloneString(html);     /* do not let original cart var get eaten up */
 html = customDocParse(html);  /* this will chew up the input string */
 if(html != NULL)
     {
     char *tmp = html;
-    html = htmlSanitize(html);
+    html = hubHtmlSanitizeOn() ? htmlSanitize(html) : jsStripJavascript(html);
     freeMem(tmp);
     }
 else
     html = cloneString("");   /* the doc file could not be read, see above */
 
 if ((strlen(html) > 50*1024) || startsWith("track ", html) || startsWith("browser ", html))
     {
     err = cloneString(
 	"Optional track documentation appears to be either too large (greater than 50k) or it starts with a track or browser line. "
 	"This is usually an indication that the data has been accidentally put into the documentation field. "
 	"Only html documentation is intended for this field. "
         "Please correct and re-submit.");
     html = NULL;  /* we do not want to save this bad value */
     customText = NULL;  /* trigger a return to the edit page */
     }