b6f15357f432f1c218fabcb0d53777322e357c00 max Tue Sep 29 15:43:57 2026 -0700 hgGeneGraph: bind the feedback-form arithmetic check to its target and a real secret Reuses a per-render hash instead of a fixed public constant, and ties it to the specific gene pair rather than just the answer, refs #38399 diff --git src/hg/hgGeneGraph/hgGeneGraph src/hg/hgGeneGraph/hgGeneGraph index 0f87b36bf9d..5fcc08b921c 100755 --- src/hg/hgGeneGraph/hgGeneGraph +++ src/hg/hgGeneGraph/hgGeneGraph @@ -318,30 +318,39 @@ if style!=None: styleStr='style="%s" ' % style titleStr = "" if title!=None: titleStr = ' title="%s"' % title.replace('"', ' ') return '%s' % (titleStr, classStr, dataToggleStr, url, styleStr, linkName) def saltedHash(word, length=5): " return first 5 chars of salted hash " # pretty simple salt: PITX2, salting is just for the captcha inStr = word+"PITX2" hashStr = "".join(hashlib.sha1(inStr.encode("utf8")).hexdigest()[:length]).lower() return hashStr +def captchaHashFor(param, answer): + """ Hash of an arithmetic-captcha answer, bound to the specific removal target and a + secret from hg.conf.private, so one solved answer is only good for the one form it was + shown on. param is length-prefixed so a differently-split (param, answer) pair cannot + concatenate to the same bytes and collide. """ + secret = cfgOption("hgGeneGraph.captchaSecret", "PITX2") + inStr = "%s%d:%s%s" % (secret, len(param), param, answer) + return hashlib.sha1(inStr.encode("utf8")).hexdigest()[:10] + def reqMinSupp(links, minArtSupp, maxResCount, targetGene): """ remove all 'text mining only' links with less than minArtSupp supporting documents The only exception is targetGene which we always want to stay connected Also remove links that are PPI-only and have a high minResCount. """ newLinks = defaultdict(set) genes = set() targetConns = {} for genePair, linkData in links.items(): docCount, dbCount, tagSet, pairMinResCount = linkData[:4] if targetGene in genePair: targetConns[genePair] = linkData # remove text-mining links with only one article @@ -1882,65 +1891,65 @@ conn = sqlConnect(GGDB) rows = queryEventText(conn, causeGene, themeGene) print ("
") print ("Thank you for reporting errors, e.g.") print("
")
print ("Optional comment:
")
print(('