beb596d6144e0deb9ce96c5955c71e6d5f4eaec9 braney Sat Sep 26 13:01:02 2026 -0700 trackHub: add an hg.conf switch for hub description page handling, refs #38126 hubHtmlSanitizeOn() in trackHub.c reads the hg.conf setting hubHtmlSanitize, default off, and the description page code in lib and cgilib asks it. With the setting off, that code behaves as it did in v503. hubCheck follows the same setting. diff --git src/hg/lib/trackHub.c src/hg/lib/trackHub.c index 64f02b61594..7ba1eba952f 100644 --- src/hg/lib/trackHub.c +++ src/hg/lib/trackHub.c @@ -994,30 +994,37 @@ static void requireBarChartBars(struct trackHub *hub, struct trackHubGenome *genome, struct trackDb *tdb) /* Fetch setting(s) or give an error message */ { if (!trackDbSetting(tdb, BAR_CHART_CATEGORY_URL) && !trackDbSetting(tdb, BAR_CHART_CATEGORY_LABELS)) errAbort("BarChart track '%s' is missing either %s or %s setting. Please add one of those settings to the appropriate stanza", tdb->track, BAR_CHART_CATEGORY_LABELS, BAR_CHART_CATEGORY_URL); } boolean trackHubBigNetEnabled() /* Return TRUE if the bigNet track type is turned on. Off unless hg.conf says * bigNet=on. Everything that accepts or advertises the type asks this. */ { return cfgOptionBooleanDefault("bigNet", FALSE); } +boolean hubHtmlSanitizeOn() +/* Return TRUE if description HTML from hubs and custom tracks goes through htmlSanitize. + * Off unless hg.conf says hubHtmlSanitize=on. */ +{ +return cfgOptionBooleanDefault("hubHtmlSanitize", FALSE); +} + static void validateOneTrack( struct trackHub *hub, struct trackHubGenome *genome, struct trackDb *tdb) /* Validate a track's trackDb entry. */ { /* Check for existence of fields required in all tracks */ requiredSetting(hub, genome, tdb, "shortLabel"); char *shortLabel = trackDbSetting(tdb, "shortLabel"); memSwapChar(shortLabel, strlen(shortLabel), '\t', ' '); requiredSetting(hub, genome, tdb, "longLabel"); char *longLabel = trackDbSetting(tdb, "longLabel"); memSwapChar(longLabel, strlen(longLabel), '\t', ' '); /* Forbid any dangerous settings that should not be allowed */ forbidSetting(hub, genome, tdb, "idInUrlSql"); @@ -1342,40 +1349,50 @@ { safef(buffer, sizeof buffer, "%s.html", url); fixedUrl = buffer; } char *html = udcFileReadAllIfExists(fixedUrl, NULL, 0, NULL); freez(&url); return html; } void trackHubAddOneDescription(char *trackDbFile, struct trackDb *tdb) /* Fetch tdb->track's html description and store in tdb->html. */ { char *html = trackHubDescriptionText(trackDbFile, tdb); if (html == NULL) return; /* no page of its own, so leave any it inherited alone */ +if (hubHtmlSanitizeOn()) + { tdb->html = htmlSanitize(html); freeMem(html); } +else + tdb->html = html; +} struct slName *trackHubDescriptionRemovals(char *trackDbFile, struct trackDb *tdb) /* Return a list of messages naming the parts of tdb's description page that we do not * print, or NULL if we print all of it. */ { char *html = trackHubDescriptionText(trackDbFile, tdb); struct slName *removed = NULL; +if (!hubHtmlSanitizeOn()) + { + freeMem(html); + return NULL; + } char *clean = htmlSanitizeReport(html, &removed); freeMem(html); freeMem(clean); return removed; } void trackHubAddDescription(char *trackDbFile, struct trackDb *tdb) /* Fetch tdb->track's html description (or nearest ancestor's non-empty description) * and store in tdb->html. */ { trackHubAddOneDescription(trackDbFile, tdb); if (isEmpty(tdb->html)) { struct trackDb *parent; for (parent = tdb->parent; isEmpty(tdb->html) && parent != NULL; parent = parent->parent)