7b3bd7a453e354dc0d4003bc7c65b073866f16f4
braney
  Tue Sep 29 13:35:06 2026 -0700
hgGateway: read a hub assembly's description the way other hub pages are read, refs #38430

diff --git src/hg/hgGateway/hgGateway.c src/hg/hgGateway/hgGateway.c
index a0d73f49c51..83b9bc3e546 100644
--- src/hg/hgGateway/hgGateway.c
+++ src/hg/hgGateway/hgGateway.c
@@ -15,57 +15,65 @@
 #include "cheapcgi.h"
 #include "errCatch.h"
 #include "googleAnalytics.h"
 #include "hCommon.h"
 #include "hgConfig.h"
 #include "hdb.h"
 #include "htmshell.h"
 #include "hubConnect.h"
 #include "hui.h"
 #include "jsHelper.h"
 #include "jsonParse.h"
 #include "obscure.h"  // for readInGulp
 #include "regexHelper.h"
 #include "suggest.h"
 #include "trackHub.h"
+#include "htmlSanitize.h"
 #include "web.h"
 #include "botDelay.h"
 #include "genark.h"
 #include "assemblyList.h"
 #include <limits.h>
 
 /* Global Variables */
 struct cart *cart = NULL;             /* CGI and other variables */
 struct hash *oldVars = NULL;          /* Old contents of cart before it was updated by CGI */
 
 static boolean issueBotWarning = FALSE;
 static int measureTiming = 0;
 static long enteredMainTime = 0;
 
 #define SEARCH_TERM "hggw_term"
 
 static char *maybeGetDescriptionText(char *db)
 /* Slurp the description.html file for db into a string (if possible, don't die if
  * we can't read it) and return it. */
 {
 struct errCatch *errCatch = errCatchNew();
 char *descText = NULL;
 if (errCatchStart(errCatch))
     {
     char *htmlPath = hHtmlPath(db);
     if (isNotEmpty(htmlPath))
         descText = udcFileReadAll(htmlPath, NULL, 0, NULL);
+    /* A hub's page gets the same treatment here as everywhere else we show one. */
+    if (descText != NULL && trackHubDatabase(db) && hubHtmlSanitizeOn())
+        {
+        char *clean = htmlSanitize(descText);
+        freeMem(descText);
+        descText = clean;
+        }
     }
 errCatchEnd(errCatch);
 // Just ignore errors for now.
 return descText;
 }
 
 static int trackHubCountAssemblies(struct trackHub *hub)
 /* Return the number of hub's genomes that are hub assemblies, i.e. that have a twoBitPath. */
 {
 int count = 0;
 struct trackHubGenome *genome;
 for (genome = hub->genomeList;  genome != NULL;  genome = genome->next)
     {
     if (isNotEmpty(genome->twoBitPath))
         count++;