983b7eff4b1c516c9cb7bb56cc1399216a127d51 max Wed Aug 19 04:02:39 2026 -0700 address v503 preview1 code review (#38141): escaping and oauth fixes Fixes the six items Brian raised reviewing the XSS sweep (#38057) and the BLAT-results group work (#38086): - hgGenome/configure.c, hgPal.c: drop htmlEncode() on cartWebStart title args; cartWebStart already escapes the title, so this was double-escaping. - hgSession.c doReSaveSession: htmlEncode the user name and pass the encoded name to getSessionLink (same fix already applied at line 1544). - hgUserSuggestion.c printInvalidForm: cgiEncode the five cart values echoed into the mailto: href (reachable on the robot/captcha path). - hgSearch.c: cgiEncode db for the hgTracks URL query parameter instead of reusing the JSON-escaped copy meant for the JS string literal. - hgLogin.c oauthReturn: clone oauth_provider before cartRemove frees it, so the later oauthFetchIdentity call is not a read-after-free. - customFactory.c checkGroup: only accept group=blat when blatResultsGroup is on, matching hgTracks; otherwise the group is never created and the track would orphan into 'other'. refs #38141, refs #38057, refs #38086 diff --git src/hg/hgPal/hgPal.c src/hg/hgPal/hgPal.c index 25e466fcbb0..93b91c94071 100644 --- src/hg/hgPal/hgPal.c +++ src/hg/hgPal/hgPal.c @@ -1,68 +1,68 @@ /* hgPal - URL entry point to library pal routines */ /* Copyright (C) 2013 The Regents of the University of California * See kent/LICENSE or http://genome.ucsc.edu/license/ for licensing information. */ #include "common.h" #include "htmshell.h" #include "cart.h" #include "cheapcgi.h" #include "web.h" #include "hdb.h" #include "hui.h" #include "pal.h" char *excludeVars[] = {"Submit", "submit", NULL,}; void addOurButtons() { cgiMakeButton("Submit", "Submit"); } void doMiddle(struct cart *cart) /* Set up globals and make web page */ { char *track = cartString(cart, "g"); char *chrom = cartOptionalString(cart, "c"); char *item = cartOptionalString(cart, "i"); int start = cartInt(cart, "l"); int end = cartInt(cart, "r"); char *database; char *genome; getDbAndGenome(cart, &database, &genome, NULL); struct sqlConnection *conn = hAllocConn(database); -cartWebStart(cart, database, "Other Species Alignments for %s %s",htmlEncode(track),htmlEncode(item)); // user input into title, escape (XSS) +cartWebStart(cart, database, "Other Species Alignments for %s %s",track,item); // cartWebStart escapes the title itself /* output the option selection dialog */ palOptions(cart, conn, addOurButtons, NULL); printf("For information about output data format see the " "User's Guide
"); struct bed *bed; AllocVar(bed); bed->name = item; bed->chromStart = start; bed->chromEnd = end; bed->chrom = chrom; printf("
");
 /* output the alignments */
 int result =palOutPredsInBeds(conn, cart, bed, track);
 printf("
"); if (result == 0) printf("No coding region in gene '%s'
",htmlEncode(item)); cartHtmlEnd(); } int main(int argc, char *argv[]) /* Process command line. */ { long enteredMainTime = clock1000(); cgiSpoof(&argc, argv); cartEmptyShell(doMiddle, hUserCookie(), excludeVars, NULL); cgiExitTime("hgPal", enteredMainTime); return 0; }