1c7ec830118f006d5fde9d8cdb36596edcf6e055
braney
Tue Aug 18 12:03:17 2026 -0700
cheapcgi, hui: encode a bigBed-derived form control name, refs #38123
diff --git src/hg/lib/hui.c src/hg/lib/hui.c
index 743ed56095a..fe59d53ff79 100644
--- src/hg/lib/hui.c
+++ src/hg/lib/hui.c
@@ -4462,34 +4462,35 @@
printf(" all ");
cgiMakeRadioButton(cartSettingString, FILTERBY_MULTIPLE_LIST_OR, sameString(setting, FILTERBY_MULTIPLE_LIST_OR));
printf(" one or more match ");
}
}
puts("");
}
puts("
");
int ix=0;
for (filterBy = filterBySet; filterBy != NULL; filterBy = filterBy->next, ix++)
{
char *setting = getFilterType(cart, tdb, filterBy->column, FILTERBY_DEFAULT);
puts("");
// value is always "All", even if label is different, to simplify javascript code
int valIx = 1;
+ // htmlName holds the field name, which for a hub bigBed comes from the hub's autoSql
if (filterByColumnIsMultiple(cart, tdb, setting))
- printf( "\n", selectIdPrefix,ix,filterBy->htmlName);
+ printf( "\n", selectIdPrefix,ix,htmlEncode(filterBy->htmlName));
else
- printf( "\n", selectIdPrefix,ix,filterBy->htmlName);
+ printf( "\n", selectIdPrefix,ix,htmlEncode(filterBy->htmlName));
printf("%s \n", (filterByAllChosen(filterBy)?" SELECTED":""), allLabel);
struct slName *slValue;
for (slValue=filterBy->slValues;slValue!=NULL;slValue=slValue->next,valIx++)
{
char varName[32];
char *label = NULL;
char *name = NULL;
if (filterBy->useIndex)
{
safef(varName, sizeof(varName), "%d",valIx);
name = varName;
label = slValue->name;
}