9cc5eeb88ad0d6bea3449fcc1de1fbe54d79dafd
braney
  Sat Sep 26 17:47:52 2026 -0700
docent regression scripts for hgLogin and a batch of page fields, refs #38252, #38011, #38057

diff --git src/hg/utils/docent/tests/regress/rm38011.docent.yaml src/hg/utils/docent/tests/regress/rm38011.docent.yaml
new file mode 100644
index 00000000000..19ddf5c50c5
--- /dev/null
+++ src/hg/utils/docent/tests/regress/rm38011.docent.yaml
@@ -0,0 +1,68 @@
+# #38011 -- hgLogin pages should show the values a request hands them as plain text.
+#
+# Fixed in 1a7b4e1d39c and 67f89eb6f4f, both in origin/v503_branch and neither in
+# origin/v502_branch.
+#
+# Each step opens a login page with a test value in its fields, then checks that the value
+# is shown as text: `noHas:` checks that no element with the test id appeared, and `value:`
+# checks that the field holds the whole value. The `value:` check also fails on a page
+# that was not drawn at all, so `noHas:` cannot pass on an empty page.
+#
+# The returnto steps check that a returnto which is not a plain URL is refused with
+# "Invalid returnto URL", and that an ordinary one, query string and all, still reaches the
+# Cancel link unchanged. The second check keeps a fix that refused every returnto from
+# passing.
+proof:
+  - "assertion-only 2026-09-26 -- written from 1a7b4e1d39c and 67f89eb6f4f, after the fix shipped in v503"
+  - "release-ab 2026-09-26 -- fails on v502_branch (park 38304); run one page at a time there, every page step fails for its own reason and the ordinary-returnto control passes on both; passes on genome-test"
+
+target: genome-test
+db: hg38
+reset: true
+fast: true
+steps:
+  # The login page: the user name field.
+  - goto: "/cgi-bin/hgLogin?hgLogin.do.displayLoginPage=1&hgLogin_userName=%22%3E%3Cb%20id%3Ddocentxss38011%3Ex%3C%2Fb%3E"
+  - expect:
+      noHas: "#docentxss38011"
+      value: {sel: 'input[name="hgLogin_userName"]', is: '"><b id=docentxss38011>x</b>'}
+
+  # The account-help page: the user name and the email fields.
+  - goto: "/cgi-bin/hgLogin?hgLogin.do.displayAccHelpPage=1&hgLogin_userName=%22%3E%3Cb%20id%3Ddocentxss38011%3Ex%3C%2Fb%3E&hgLogin_email=%22%3E%3Cb%20id%3Ddocentxss38011%3Ex%3C%2Fb%3E"
+  - expect:
+      noHas: "#docentxss38011"
+      value:
+        - {sel: 'input[name="hgLogin_userName"]', is: '"><b id=docentxss38011>x</b>'}
+        - {sel: 'input[name="hgLogin_email"]', is: '"><b id=docentxss38011>x</b>'}
+
+  # The sign-up page.
+  - goto: "/cgi-bin/hgLogin?hgLogin.do.signupPage=1&hgLogin_userName=%22%3E%3Cb%20id%3Ddocentxss38011%3Ex%3C%2Fb%3E&hgLogin_email=%22%3E%3Cb%20id%3Ddocentxss38011%3Ex%3C%2Fb%3E"
+  - expect:
+      noHas: "#docentxss38011"
+      value:
+        - {sel: 'input[name="hgLogin_userName"]', is: '"><b id=docentxss38011>x</b>'}
+        - {sel: 'input[name="hgLogin_email"]', is: '"><b id=docentxss38011>x</b>'}
+
+  # The "mail sent" page shows the address in body text.
+  - goto: "/cgi-bin/hgLogin?hgLogin.do.displayMailSuccess=1&hgLogin_sendMailTo=%22%3E%3Cb%20id%3Ddocentxss38011%3Ex%3C%2Fb%3E"
+  - expect:
+      noHas: "#docentxss38011"
+      text: 'for "><b id=docentxss38011>x</b> have been sent'
+
+  # A returnto that is not a plain URL is refused.
+  - goto: "/cgi-bin/hgLogin?hgLogin.do.displayAccHelpPage=1&returnto=https%3A%2F%2Fgenome-test.gi.ucsc.edu%2Fcgi-bin%2FhgSession%3Fx%22%3E%3Cb%20id%3Ddocentxss38011%3Ex%3C%2Fb%3E"
+  - expect:
+      noHas: "#docentxss38011"
+      text: "Invalid returnto URL"
+
+  # So is one with a scheme other than http(s).
+  - goto: "/cgi-bin/hgLogin?hgLogin.do.displayAccHelpPage=1&returnto=javascript%3Aalert(38011)"
+  - expect:
+      noHas: 'a[href^="javascript:alert"]'
+      text: "Invalid returnto URL"
+
+  # An ordinary returnto still works, query string and all.
+  - goto: "/cgi-bin/hgLogin?hgLogin.do.displayAccHelpPage=1&returnto=https%3A%2F%2Fgenome-test.gi.ucsc.edu%2Fcgi-bin%2FhgSession%3Fx%3D1%26y%3D2"
+  - expect:
+      has: 'a[href="https://genome-test.gi.ucsc.edu/cgi-bin/hgSession?x=1&y=2"]'
+      noText: "Invalid returnto URL"