0cfbb0ae0beabd4e52ccad30dd876d4d42795cba max Tue Sep 29 23:32:19 2026 -0700 hgTracks: html-encode the values the track download dialog builds into its markup The dialog assembles its html by string concatenation, and several of the values that go in are not written by the code: the track names and short labels come from trackDb, which for a hub means from the hub, the assembly name can carry a hub's own naming, and the region line is whatever the position box holds. They now go through htmlEncode() from utils.js, the shared helper, which covers both element text and single-quoted attribute values, so a label or a name comes out as the text it is meant to be. refs #38226 diff --git src/hg/js/hgTracks.js src/hg/js/hgTracks.js index ee62c57660f..ba08d958c70 100644 --- src/hg/js/hgTracks.js +++ src/hg/js/hgTracks.js @@ -8090,83 +8090,86 @@ // pane rather than in the dialog body, because the body scrolls once the // track list is long and a message the user has to scroll to find is no // better than no message. The Download button gets an id so that it can be // disabled while the file is being built. dialogWrap.find(".ui-dialog-buttonpane button").first().attr("id", "downloadTracksGo"); dialogWrap.find(".ui-dialog-buttonset").after( ""); } // the strand the browser is showing, which the Reverse button flips let strandStr = hgTracks.revCmplDisp ? "(- strand)" : "(+ strand)"; htmlStr = "
Use this selection window to download track data for the current region:" +
// the position is data, not prose, so it gets the monospace treatment and a
// line of its own
"
" + genomePos.get() + " " + strandStr + "
" +
+ "font-weight: bold\">" + htmlEncode(genomePos.get()) + " " + strandStr +
+ "
" +
"Large regions may be slow to download.