2bdcf31450f998eff8aaf558eabdae8aa949f3af
braney
  Mon Sep 28 10:07:57 2026 -0700
hgConfCatalog: classify hubHtmlSanitize as a release gate, refs #37925 #38126

The nightly auto-register had written the row but left it unclassified,
so the reconcile flagged it.  It ships off in v504 and is meant to flip on
in v505, so it is a gate.

diff --git src/hg/utils/hgConfCatalog/hgConfCatalog.py src/hg/utils/hgConfCatalog/hgConfCatalog.py
index 22020959ca8..093a34bbfcf 100755
--- src/hg/utils/hgConfCatalog/hgConfCatalog.py
+++ src/hg/utils/hgConfCatalog/hgConfCatalog.py
@@ -599,30 +599,39 @@
           note="A green \"reference\" word before an assembly in the "
                "gateway search results when NCBI's refSeqCategory for it "
                "is \"reference\".  Only the GenArk matches from "
                "assemblyList can carry it; a dbDb assembly and a match "
                "from the NCBI assembly search never do.  With the gate "
                "off, isReference is always FALSE in the JSON and "
                "autocompleteCat.js draws no badge and no mouseover."),
         h("denseClick", "flag", "hg/hgTracks/simpleTracks.c", default="FALSE",
           role="gate", verified=True, ticket="38364",
           note="One clickable map box per item in a dense row, so a click "
                "reaches the item's details page instead of expanding the "
                "track.  Read once, in denseClickEnabled().  A gate over the "
                "whole feature: with it on, a track still has to opt in with "
                "the denseClick trackDb setting, and with it off no track "
                "gets it whatever its trackDb says."),
+        h("hubHtmlSanitize", "flag", "hg/lib/trackHub.c", default="FALSE",
+          role="gate", verified=True, ticket="38126",
+          note="Passes description HTML from hubs and custom tracks through "
+               "htmlSanitize() on the way in.  Read once, in "
+               "hubHtmlSanitizeOn(), which every entry point and hubCheck "
+               "ask.  Off is the older behavior: customTrack.c falls back to "
+               "jsStripJavascript().  Added off for v504 because QA found "
+               "pages the filter changes; the default is meant to flip to "
+               "TRUE in v505 once those are fixed."),
     ],
 }
 
 
 # ---------------------------------------------------------------------------
 # mirror knobs: boolean flags that are meant to live forever
 # ---------------------------------------------------------------------------
 
 MIRROR_KNOBS = {
     "what": "Settings that are legitimate, permanent deployment switches.  "
             "Nearly all are boolean flags, and those are listed explicitly so "
             "the sunset report does not nag about them; a few are strings that "
             "choose between behaviours rather than turning one off, and those "
             "carry no gate/knob role because only booleans have one.",
     "vars": [
@@ -1708,37 +1717,30 @@
     "what": "Settings the tree reads that --auto-register wrote down without "
             "a person's help, so no read goes unrecorded while it waits to be "
             "classified.  Everything in a row here is a fact copied off the "
             "call: name, call site, and the compiled-in default when it is a "
             "literal.  Nothing here is a judgement.  A row leaves this "
             "section by hand, once somebody reads the call site and can say "
             "what the setting is for, whether a boolean is a gate or a knob, "
             "and whether a mirror operator would want it; then it moves to "
             "the section it belongs in with verified=True.  Rows are not "
             "expected to stay here, and --reconcile counts every one of them "
             "as needing attention.",
     "vars": [
         # --auto-register inserts new rows directly below this line.  Leave the
         # marker in place; it is how the writer finds its way in.
         # AUTO-REGISTER INSERTION POINT
-        h("hubHtmlSanitize", "flag", "hg/lib/trackHub.c", default="FALSE",
-          ticket="38126",
-          note="Written down by --auto-register, not yet reviewed by a "
-               "person.  Read with cfgOptionBooleanDefault in "
-               "hg/lib/trackHub.c.  Came in at beb596d6144, trackHub: add an "
-               "hg.conf switch for hub description page handling, refs "
-               "#38126.  Needs a description and a gate or knob call."),
     ],
 }
 
 
 # ---------------------------------------------------------------------------
 # assembly
 # ---------------------------------------------------------------------------
 
 SECTIONS = [
     ("Release gates", RELEASE_GATES),
     ("Mirror knobs", MIRROR_KNOBS),
     ("Database connections", DATABASE),
     ("hgcentral tables", CENTRAL_TABLES),
     ("Paths and caches", PATHS),
     ("Limits and load control", LIMITS),