983b7eff4b1c516c9cb7bb56cc1399216a127d51
max
Wed Aug 19 04:02:39 2026 -0700
address v503 preview1 code review (#38141): escaping and oauth fixes
Fixes the six items Brian raised reviewing the XSS sweep (#38057) and the
BLAT-results group work (#38086):
- hgGenome/configure.c, hgPal.c: drop htmlEncode() on cartWebStart title args;
cartWebStart already escapes the title, so this was double-escaping.
- hgSession.c doReSaveSession: htmlEncode the user name and pass the encoded
name to getSessionLink (same fix already applied at line 1544).
- hgUserSuggestion.c printInvalidForm: cgiEncode the five cart values echoed
into the mailto: href (reachable on the robot/captcha path).
- hgSearch.c: cgiEncode db for the hgTracks URL query parameter instead of
reusing the JSON-escaped copy meant for the JS string literal.
- hgLogin.c oauthReturn: clone oauth_provider before cartRemove frees it, so
the later oauthFetchIdentity call is not a read-after-free.
- customFactory.c checkGroup: only accept group=blat when blatResultsGroup is
on, matching hgTracks; otherwise the group is never created and the track
would orphan into 'other'.
refs #38141, refs #38057, refs #38086
diff --git src/hg/hgPal/hgPal.c src/hg/hgPal/hgPal.c
index 25e466fcbb0..93b91c94071 100644
--- src/hg/hgPal/hgPal.c
+++ src/hg/hgPal/hgPal.c
@@ -1,68 +1,68 @@
/* hgPal - URL entry point to library pal routines */
/* Copyright (C) 2013 The Regents of the University of California
* See kent/LICENSE or http://genome.ucsc.edu/license/ for licensing information. */
#include "common.h"
#include "htmshell.h"
#include "cart.h"
#include "cheapcgi.h"
#include "web.h"
#include "hdb.h"
#include "hui.h"
#include "pal.h"
char *excludeVars[] = {"Submit", "submit", NULL,};
void addOurButtons()
{
cgiMakeButton("Submit", "Submit");
}
void doMiddle(struct cart *cart)
/* Set up globals and make web page */
{
char *track = cartString(cart, "g");
char *chrom = cartOptionalString(cart, "c");
char *item = cartOptionalString(cart, "i");
int start = cartInt(cart, "l");
int end = cartInt(cart, "r");
char *database;
char *genome;
getDbAndGenome(cart, &database, &genome, NULL);
struct sqlConnection *conn = hAllocConn(database);
-cartWebStart(cart, database, "Other Species Alignments for %s %s",htmlEncode(track),htmlEncode(item)); // user input into title, escape (XSS)
+cartWebStart(cart, database, "Other Species Alignments for %s %s",track,item); // cartWebStart escapes the title itself
/* output the option selection dialog */
palOptions(cart, conn, addOurButtons, NULL);
printf("For information about output data format see the "
"User's Guide
");
struct bed *bed;
AllocVar(bed);
bed->name = item;
bed->chromStart = start;
bed->chromEnd = end;
bed->chrom = chrom;
printf("
");
/* output the alignments */
int result =palOutPredsInBeds(conn, cart, bed, track);
printf("");
if (result == 0)
printf("No coding region in gene '%s'