0cfbb0ae0beabd4e52ccad30dd876d4d42795cba max Tue Sep 29 23:32:19 2026 -0700 hgTracks: html-encode the values the track download dialog builds into its markup The dialog assembles its html by string concatenation, and several of the values that go in are not written by the code: the track names and short labels come from trackDb, which for a hub means from the hub, the assembly name can carry a hub's own naming, and the region line is whatever the position box holds. They now go through htmlEncode() from utils.js, the shared helper, which covers both element text and single-quoted attribute values, so a label or a name comes out as the text it is meant to be. refs #38226 diff --git src/hg/js/hgTracks.js src/hg/js/hgTracks.js index ee62c57660f..ba08d958c70 100644 --- src/hg/js/hgTracks.js +++ src/hg/js/hgTracks.js @@ -8090,83 +8090,86 @@ // pane rather than in the dialog body, because the body scrolls once the // track list is long and a message the user has to scroll to find is no // better than no message. The Download button gets an id so that it can be // disabled while the file is being built. dialogWrap.find(".ui-dialog-buttonpane button").first().attr("id", "downloadTracksGo"); dialogWrap.find(".ui-dialog-buttonset").after( ""); } // the strand the browser is showing, which the Reverse button flips let strandStr = hgTracks.revCmplDisp ? "(- strand)" : "(+ strand)"; htmlStr = "

Use this selection window to download track data for the current region:" + // the position is data, not prose, so it gets the monospace treatment and a // line of its own "
" + genomePos.get() + "  " + strandStr + "
" + + "font-weight: bold\">" + htmlEncode(genomePos.get()) + "  " + strandStr + + "
" + "Large regions may be slow to download.

"; // the output format comes first: it decides which tracks can be downloaded at all htmlStr += "
"; htmlStr += ""; htmlStr += ""; // an option of the format, so it sits with it and disappears with it htmlStr += "
"; htmlStr += ""; htmlStr += ""; htmlStr += "
"; // its own block, so that it does not move up next to the format select when the // column header option above it is hidden htmlStr += "
"; htmlStr += ""; // undecoratedTrack strips the hub__ that a hub assembly's name carries, the // hub id is this browser's cart detail and means nothing in a file name htmlStr += ""; + " value='" + htmlEncode(undecoratedTrack(getDb())) + ".tracks'>"; htmlStr += "
"; htmlStr += "
"; htmlStr += "
"; _.each(hgTracks.trackDb, function(track, trackName) { showDisabledMsg = false; if (!trackName.includes("Squish") && trackName !== "ruler" && track.visibility > 0) { - htmlStr += ""; + htmlStr += ""; htmlStr += ""; if (showDisabledMsg) { - htmlStr += " (?)"; + htmlStr += " (?)"; } htmlStr += "
"; } }); htmlStr += "
"; htmlStr += "
" + " " + "" + "
"; if (withGenbank) { htmlStr += "
The GenBank file also " + "contains the DNA sequence of the region, always on the forward strand, even " + "when the browser is showing the reverse complement. Tracks with numerical " + "data, e.g. bigWigs, have no GenBank equivalent and are greyed out." +