983b7eff4b1c516c9cb7bb56cc1399216a127d51
max
  Wed Aug 19 04:02:39 2026 -0700
address v503 preview1 code review (#38141): escaping and oauth fixes

Fixes the six items Brian raised reviewing the XSS sweep (#38057) and the
BLAT-results group work (#38086):

- hgGenome/configure.c, hgPal.c: drop htmlEncode() on cartWebStart title args;
cartWebStart already escapes the title, so this was double-escaping.
- hgSession.c doReSaveSession: htmlEncode the user name and pass the encoded
name to getSessionLink (same fix already applied at line 1544).
- hgUserSuggestion.c printInvalidForm: cgiEncode the five cart values echoed
into the mailto: href (reachable on the robot/captcha path).
- hgSearch.c: cgiEncode db for the hgTracks URL query parameter instead of
reusing the JSON-escaped copy meant for the JS string literal.
- hgLogin.c oauthReturn: clone oauth_provider before cartRemove frees it, so
the later oauthFetchIdentity call is not a read-after-free.
- customFactory.c checkGroup: only accept group=blat when blatResultsGroup is
on, matching hgTracks; otherwise the group is never created and the track
would orphan into 'other'.

refs #38141, refs #38057, refs #38086

diff --git src/hg/hgPal/hgPal.c src/hg/hgPal/hgPal.c
index 25e466fcbb0..93b91c94071 100644
--- src/hg/hgPal/hgPal.c
+++ src/hg/hgPal/hgPal.c
@@ -1,68 +1,68 @@
 /* hgPal - URL entry point to library pal routines */
 
 /* Copyright (C) 2013 The Regents of the University of California 
  * See kent/LICENSE or http://genome.ucsc.edu/license/ for licensing information. */
 #include "common.h"
 #include "htmshell.h"
 #include "cart.h"
 #include "cheapcgi.h"
 #include "web.h"
 #include "hdb.h"
 #include "hui.h"
 #include "pal.h"
 
 
 char *excludeVars[] = {"Submit", "submit", NULL,};
 
 void addOurButtons()
 {
 cgiMakeButton("Submit", "Submit");
 }
 
 void doMiddle(struct cart *cart)
 /* Set up globals and make web page */
 {
 char *track = cartString(cart, "g");
 char *chrom = cartOptionalString(cart, "c");
 char *item = cartOptionalString(cart, "i");
 int start = cartInt(cart, "l");
 int end = cartInt(cart, "r");
 char *database;
 char *genome;
 
 getDbAndGenome(cart, &database, &genome, NULL);
 struct sqlConnection *conn = hAllocConn(database);
-cartWebStart(cart, database, "Other Species Alignments for %s %s",htmlEncode(track),htmlEncode(item)); // user input into title, escape (XSS)
+cartWebStart(cart, database, "Other Species Alignments for %s %s",track,item); // cartWebStart escapes the title itself
 
 /* output the option selection dialog */
 palOptions(cart, conn, addOurButtons, NULL);
 
 printf("For information about output data format see the "
   "<A HREF=\"../goldenPath/help/hgTablesHelp.html#FASTA\">User's Guide</A><BR>");
 
 struct bed *bed;
 AllocVar(bed);
 bed->name = item;
 bed->chromStart = start;
 bed->chromEnd = end;
 bed->chrom = chrom;
 
 printf("<pre>");
 /* output the alignments */
 int result =palOutPredsInBeds(conn, cart, bed, track);
 printf("</pre>");
 if (result == 0)
     printf("<B>No coding region in gene '%s'</B><BR>",htmlEncode(item));
 
 cartHtmlEnd();
 }
 
 int main(int argc, char *argv[])
 /* Process command line. */
 {
 long enteredMainTime = clock1000();
 cgiSpoof(&argc, argv);
 cartEmptyShell(doMiddle, hUserCookie(), excludeVars, NULL);
 cgiExitTime("hgPal", enteredMainTime);
 return 0;
 }