@@ -20,6 +20,11 @@ class Save extends \Magento\Customer\Controller\Adminhtml\Group implements HttpP
20
20
*/
21
21
protected $ dataObjectProcessor ;
22
22
23
+ /**
24
+ * @var \Magento\Framework\Escaper
25
+ */
26
+ protected $ escaper ;
27
+
23
28
/**
24
29
*
25
30
* @param \Magento\Backend\App\Action\Context $context
@@ -29,6 +34,7 @@ class Save extends \Magento\Customer\Controller\Adminhtml\Group implements HttpP
29
34
* @param \Magento\Backend\Model\View\Result\ForwardFactory $resultForwardFactory
30
35
* @param \Magento\Framework\View\Result\PageFactory $resultPageFactory
31
36
* @param \Magento\Framework\Reflection\DataObjectProcessor $dataObjectProcessor
37
+ * @param \Magento\Framework\Escaper $escaper
32
38
*/
33
39
public function __construct (
34
40
\Magento \Backend \App \Action \Context $ context ,
@@ -37,9 +43,11 @@ public function __construct(
37
43
GroupInterfaceFactory $ groupDataFactory ,
38
44
\Magento \Backend \Model \View \Result \ForwardFactory $ resultForwardFactory ,
39
45
\Magento \Framework \View \Result \PageFactory $ resultPageFactory ,
40
- \Magento \Framework \Reflection \DataObjectProcessor $ dataObjectProcessor
46
+ \Magento \Framework \Reflection \DataObjectProcessor $ dataObjectProcessor ,
47
+ \Magento \Framework \Escaper $ escaper
41
48
) {
42
49
$ this ->dataObjectProcessor = $ dataObjectProcessor ;
50
+ $ this ->escaper = $ escaper ;
43
51
parent ::__construct (
44
52
$ context ,
45
53
$ coreRegistry ,
@@ -96,7 +104,7 @@ public function execute()
96
104
$ this ->messageManager ->addSuccessMessage (__ ('You saved the customer group. ' ));
97
105
$ resultRedirect ->setPath ('customer/group ' );
98
106
} catch (\Exception $ e ) {
99
- $ this ->messageManager ->addErrorMessage ($ e ->getMessage ());
107
+ $ this ->messageManager ->addErrorMessage ($ this -> escaper -> escapeHtml ( $ e ->getMessage () ));
100
108
if ($ customerGroup != null ) {
101
109
$ this ->storeCustomerGroupDataToSession (
102
110
$ this ->dataObjectProcessor ->buildOutputDataArray (
0 commit comments