2cdae04ddc1e46cdfc2e5e8cf479cbbbb616ad10 chmalee Tue Sep 22 15:55:10 2026 -0700 htmlSanitize tooltips before printing them into the page, refs #38226 diff --git src/hg/js/utils.js src/hg/js/utils.js index 03cb16912fe..53836611633 100644 --- src/hg/js/utils.js +++ src/hg/js/utils.js @@ -4039,33 +4039,33 @@ if (typeof greyBarIcons !== 'undefined' && greyBarIcons === true) { // show the gear icon over the grey bar to bring up the context menu let tdBtn = document.getElementById("td_btn_" + id); if (tdBtn) { let span = document.getElementById("gear_btn_" + id); if (span) { // hide any gears that may be present from dragging $(document.querySelectorAll("[id^=gear_btn]")).hide(); $(span).show(); if (!span.dataset.alreadySetup) { tdBtn.style.position = "relative"; let tdbKey = tdBtn.id.replace("td_btn_",""); let tdb = hgTracks.trackDb[tdbKey]; let tooltip = " click or right click to configure... drag to reorder"; if (typeof tdb.parentLabel !== 'undefined') { - addMouseover(span, tdb.parentLabel + tooltip + " highlighted subtracks"); + addMouseover(span, htmlEncode(tdb.parentLabel + tooltip + " highlighted subtracks")); } else { - addMouseover(span, tdb.shortLabel + tooltip); + addMouseover(span, htmlEncode(tdb.shortLabel + tooltip)); } span.addEventListener("click", (e) => { // trigger a click on the <a> of the td e.preventDefault(); e.stopPropagation(); e.stopImmediatePropagation(); const clickEvent = new MouseEvent("click", { bubbles: true, cancelable: true, view: window, clientX: tdBtn.getBoundingClientRect().left + 15, clientY: tdBtn.getBoundingClientRect().top, button: 1, }); tdBtn.children[0].dispatchEvent(clickEvent);