9cc5eeb88ad0d6bea3449fcc1de1fbe54d79dafd
braney
Sat Sep 26 17:47:52 2026 -0700
docent regression scripts for hgLogin and a batch of page fields, refs #38252, #38011, #38057
diff --git src/hg/utils/docent/tests/regress/rm38011.docent.yaml src/hg/utils/docent/tests/regress/rm38011.docent.yaml
new file mode 100644
index 00000000000..19ddf5c50c5
--- /dev/null
+++ src/hg/utils/docent/tests/regress/rm38011.docent.yaml
@@ -0,0 +1,68 @@
+# #38011 -- hgLogin pages should show the values a request hands them as plain text.
+#
+# Fixed in 1a7b4e1d39c and 67f89eb6f4f, both in origin/v503_branch and neither in
+# origin/v502_branch.
+#
+# Each step opens a login page with a test value in its fields, then checks that the value
+# is shown as text: `noHas:` checks that no element with the test id appeared, and `value:`
+# checks that the field holds the whole value. The `value:` check also fails on a page
+# that was not drawn at all, so `noHas:` cannot pass on an empty page.
+#
+# The returnto steps check that a returnto which is not a plain URL is refused with
+# "Invalid returnto URL", and that an ordinary one, query string and all, still reaches the
+# Cancel link unchanged. The second check keeps a fix that refused every returnto from
+# passing.
+proof:
+ - "assertion-only 2026-09-26 -- written from 1a7b4e1d39c and 67f89eb6f4f, after the fix shipped in v503"
+ - "release-ab 2026-09-26 -- fails on v502_branch (park 38304); run one page at a time there, every page step fails for its own reason and the ordinary-returnto control passes on both; passes on genome-test"
+
+target: genome-test
+db: hg38
+reset: true
+fast: true
+steps:
+ # The login page: the user name field.
+ - goto: "/cgi-bin/hgLogin?hgLogin.do.displayLoginPage=1&hgLogin_userName=%22%3E%3Cb%20id%3Ddocentxss38011%3Ex%3C%2Fb%3E"
+ - expect:
+ noHas: "#docentxss38011"
+ value: {sel: 'input[name="hgLogin_userName"]', is: '">x'}
+
+ # The account-help page: the user name and the email fields.
+ - goto: "/cgi-bin/hgLogin?hgLogin.do.displayAccHelpPage=1&hgLogin_userName=%22%3E%3Cb%20id%3Ddocentxss38011%3Ex%3C%2Fb%3E&hgLogin_email=%22%3E%3Cb%20id%3Ddocentxss38011%3Ex%3C%2Fb%3E"
+ - expect:
+ noHas: "#docentxss38011"
+ value:
+ - {sel: 'input[name="hgLogin_userName"]', is: '">x'}
+ - {sel: 'input[name="hgLogin_email"]', is: '">x'}
+
+ # The sign-up page.
+ - goto: "/cgi-bin/hgLogin?hgLogin.do.signupPage=1&hgLogin_userName=%22%3E%3Cb%20id%3Ddocentxss38011%3Ex%3C%2Fb%3E&hgLogin_email=%22%3E%3Cb%20id%3Ddocentxss38011%3Ex%3C%2Fb%3E"
+ - expect:
+ noHas: "#docentxss38011"
+ value:
+ - {sel: 'input[name="hgLogin_userName"]', is: '">x'}
+ - {sel: 'input[name="hgLogin_email"]', is: '">x'}
+
+ # The "mail sent" page shows the address in body text.
+ - goto: "/cgi-bin/hgLogin?hgLogin.do.displayMailSuccess=1&hgLogin_sendMailTo=%22%3E%3Cb%20id%3Ddocentxss38011%3Ex%3C%2Fb%3E"
+ - expect:
+ noHas: "#docentxss38011"
+ text: 'for ">x have been sent'
+
+ # A returnto that is not a plain URL is refused.
+ - goto: "/cgi-bin/hgLogin?hgLogin.do.displayAccHelpPage=1&returnto=https%3A%2F%2Fgenome-test.gi.ucsc.edu%2Fcgi-bin%2FhgSession%3Fx%22%3E%3Cb%20id%3Ddocentxss38011%3Ex%3C%2Fb%3E"
+ - expect:
+ noHas: "#docentxss38011"
+ text: "Invalid returnto URL"
+
+ # So is one with a scheme other than http(s).
+ - goto: "/cgi-bin/hgLogin?hgLogin.do.displayAccHelpPage=1&returnto=javascript%3Aalert(38011)"
+ - expect:
+ noHas: 'a[href^="javascript:alert"]'
+ text: "Invalid returnto URL"
+
+ # An ordinary returnto still works, query string and all.
+ - goto: "/cgi-bin/hgLogin?hgLogin.do.displayAccHelpPage=1&returnto=https%3A%2F%2Fgenome-test.gi.ucsc.edu%2Fcgi-bin%2FhgSession%3Fx%3D1%26y%3D2"
+ - expect:
+ has: 'a[href="https://genome-test.gi.ucsc.edu/cgi-bin/hgSession?x=1&y=2"]'
+ noText: "Invalid returnto URL"