|
10 | 10 | <div class="page-create-order">
|
11 | 11 | <script>
|
12 | 12 | require(["Magento_Sales/order/create/form"], function(){
|
13 |
| - order.setCurrencySymbol('<?= /* @escapeNotVerified */ $block->getCurrencySymbol($block->getCurrentCurrencyCode()) ?>') |
| 13 | + order.setCurrencySymbol('<?= $block->escapeJs($block->getCurrencySymbol($block->getCurrentCurrencyCode())) ?>') |
14 | 14 | });
|
15 | 15 | </script>
|
16 | 16 | <div class="order-details<?php if ($block->getCustomerId()): ?> order-details-existing-customer<?php endif; ?>">
|
|
35 | 35 |
|
36 | 36 | <section id="order-addresses" class="admin__page-section order-addresses">
|
37 | 37 | <div class="admin__page-section-title">
|
38 |
| - <span class="title"><?= /* @escapeNotVerified */ __('Address Information') ?></span> |
| 38 | + <span class="title"><?= $block->escapeHtml(__('Address Information')) ?></span> |
39 | 39 | </div>
|
40 | 40 | <div class="admin__page-section-content">
|
41 | 41 | <div id="order-billing_address" class="admin__page-section-item order-billing-address">
|
|
69 | 69 |
|
70 | 70 | <section class="admin__page-section order-summary">
|
71 | 71 | <div class="admin__page-section-title">
|
72 |
| - <span class="title"><?= /* @escapeNotVerified */ __('Order Total') ?></span> |
| 72 | + <span class="title"><?= $block->escapeHtml(__('Order Total')) ?></span> |
73 | 73 | </div>
|
74 | 74 | <div class="admin__page-section-content">
|
75 | 75 | <fieldset class="admin__fieldset order-history" id="order-comment">
|
76 |
| - <legend class="admin__legend"><span><?= /* @escapeNotVerified */ __('Order History') ?></span></legend> |
| 76 | + <legend class="admin__legend"><span><?= $block->escapeHtml(__('Order History')) ?></span></legend> |
77 | 77 | <br>
|
78 | 78 | <?= $block->getChildHtml('comment') ?>
|
79 | 79 | </fieldset>
|
|
88 | 88 | <div class="order-sidebar">
|
89 | 89 | <div class="store-switcher order-currency">
|
90 | 90 | <label class="admin__field-label" for="currency_switcher">
|
91 |
| - <?= /* @escapeNotVerified */ __('Order Currency:') ?> |
| 91 | + <?= $block->escapeHtml(__('Order Currency:')) ?> |
92 | 92 | </label>
|
93 | 93 | <select id="currency_switcher"
|
94 | 94 | class="admin__control-select"
|
95 | 95 | name="order[currency]"
|
96 | 96 | onchange="order.setCurrencyId(this.value); order.setCurrencySymbol(this.options[this.selectedIndex].getAttribute('symbol'));">
|
97 | 97 | <?php foreach ($block->getAvailableCurrencies() as $_code): ?>
|
98 |
| - <option value="<?= /* @escapeNotVerified */ $_code ?>"<?php if ($_code == $block->getCurrentCurrencyCode()): ?> selected="selected"<?php endif; ?> symbol="<?= /* @escapeNotVerified */ $block->getCurrencySymbol($_code) ?>"> |
99 |
| - <?= /* @escapeNotVerified */ $block->getCurrencyName($_code) ?> |
| 98 | + <option value="<?= $block->escapeHtmlAttr($_code) ?>"<?php if ($_code == $block->getCurrentCurrencyCode()): ?> selected="selected"<?php endif; ?> symbol="<?=$block->escapeHtmlAttr($block->getCurrencySymbol($_code)) ?>"> |
| 99 | + <?= $block->escapeHtml($block->getCurrencyName($_code)) ?> |
100 | 100 | </option>
|
101 | 101 | <?php endforeach; ?>
|
102 | 102 | </select>
|
|
0 commit comments