Skip to content

Commit c0cbc16

Browse files
committed
MAGETWO-99482: Use escaper methods
- use escaper methods
1 parent bd82ed4 commit c0cbc16

File tree

15 files changed

+77
-77
lines changed

15 files changed

+77
-77
lines changed

app/code/Magento/Integration/view/adminhtml/templates/integration/activate/permissions.phtml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@
1010

1111
// @codingStandardsIgnoreFile
1212
?>
13-
<div><p><?= /* @escapeNotVerified */ __('The integration you selected asks you to approve access to the following:') ?></p></div>
13+
<div><p><?= $block->escapeHtml(__('The integration you selected asks you to approve access to the following:')) ?></p></div>
1414
<div id="integration-activate-permissions-tabs">
1515
<?= $block->getChildHtml('tabs') ?>
1616
</div>

app/code/Magento/Integration/view/adminhtml/templates/integration/activate/permissions/tab/webapi.phtml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@
1313
?>
1414
<fieldset class="admin__fieldset form-inline entry-edit">
1515
<?php if ($block->isTreeEmpty()): ?>
16-
<p class="empty"><?= /* @escapeNotVerified */ __('No permissions requested') ?></p>
16+
<p class="empty"><?= $block->escapeHtml(__('No permissions requested')) ?></p>
1717
<?php else: ?>
1818
<div class="field" data-role="tree-resources-container">
1919
<div class="control">
@@ -35,8 +35,8 @@
3535
});
3636

3737
$('[data-role="resource-tree"]').rolesTree({
38-
'treeInitData': <?= /* @escapeNotVerified */ $block->getResourcesTreeJson() ?>,
39-
'treeInitSelectedData': <?= /* @escapeNotVerified */ $block->getSelectedResourcesJson() ?>
38+
'treeInitData': <?= /* @noEscape */ $block->getResourcesTreeJson() ?>,
39+
'treeInitSelectedData': <?= /* @noEscape */ $block->getSelectedResourcesJson() ?>
4040
});
4141
});
4242
</script>

app/code/Magento/Integration/view/adminhtml/templates/integration/popup_container.phtml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -20,11 +20,11 @@
2020
], function ($, Confirm) {
2121

2222
window.integration = new Integration(
23-
'<?= /* @escapeNotVerified */ $block->getUrl('*/*/permissionsDialog', ['id' => ':id', 'reauthorize' => ':isReauthorize', '_escape_params' => false]) ?>',
24-
'<?= /* @escapeNotVerified */ $block->getUrl('*/*/tokensDialog', ['id' => ':id', 'reauthorize' => ':isReauthorize', '_escape_params' => false]) ?>',
25-
'<?= /* @escapeNotVerified */ $block->getUrl('*/*/tokensExchange', ['id' => ':id', 'reauthorize' => ':isReauthorize', '_escape_params' => false]) ?>',
26-
'<?= /* @escapeNotVerified */ $block->getUrl('*/*') ?>',
27-
'<?= /* @escapeNotVerified */ $block->getUrl('*/*/loginSuccessCallback') ?>'
23+
'<?= $block->escapeUrl($block->getUrl('*/*/permissionsDialog', ['id' => ':id', 'reauthorize' => ':isReauthorize', '_escape_params' => false])) ?>',
24+
'<?= $block->escapeUrl($block->getUrl('*/*/tokensDialog', ['id' => ':id', 'reauthorize' => ':isReauthorize', '_escape_params' => false])) ?>',
25+
'<?= $block->escapeUrl($block->getUrl('*/*/tokensExchange', ['id' => ':id', 'reauthorize' => ':isReauthorize', '_escape_params' => false])) ?>',
26+
'<?= $block->escapeUrl($block->getUrl('*/*')) ?>',
27+
'<?= $block->escapeUrl($block->getUrl('*/*/loginSuccessCallback')) ?>'
2828
);
2929

3030
/**
@@ -34,8 +34,8 @@
3434
$('div#integrationGrid').on('click', 'button#delete', function (e) {
3535

3636
new Confirm({
37-
title: '<?= /* @escapeNotVerified */ __('Are you sure?') ?>',
38-
content: "<?= /* @escapeNotVerified */ __("Are you sure you want to delete this integration? You can't undo this action.") ?>",
37+
title: '<?= $block->escapeHtml(__('Are you sure?')) ?>',
38+
content: "<?= $block->escapeHtml(__("Are you sure you want to delete this integration? You can't undo this action.")) ?>",
3939
actions: {
4040
confirm: function () {
4141
$.mage.dataPost().postData({action: $(e.target).data('url'), data: {}});

app/code/Magento/Integration/view/adminhtml/templates/integration/tokens_exchange.phtml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,4 +11,4 @@
1111
// @codingStandardsIgnoreFile
1212

1313
?>
14-
<div><p><?= /* @escapeNotVerified */ __("Please setup or sign in into your 3rd party account to complete setup of this integration.") ?></p></div>
14+
<div><p><?= $block->escapeHtml(__("Please setup or sign in into your 3rd party account to complete setup of this integration.")) ?></p></div>

app/code/Magento/Integration/view/adminhtml/templates/resourcetree.phtml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -16,22 +16,22 @@
1616

1717
<fieldset class="fieldset form-inline entry-edit">
1818
<legend class="legend">
19-
<span><?= /* @escapeNotVerified */ __('Available APIs') ?></span>
19+
<span><?= $block->escapeHtml(__('Available APIs')) ?></span>
2020
</legend><br />
2121

2222
<div class="field">
23-
<label class="label" for="all_resources"><span><?= /* @escapeNotVerified */ __('Resource Access') ?></span></label>
23+
<label class="label" for="all_resources"><span><?= $block->escapeHtml(__('Resource Access')) ?></span></label>
2424

2525
<div class="control">
2626
<select id="all_resources" name="all_resources" onchange="jQuery('[data-role=tree-resources-container]').toggle()" class="select">
27-
<option value="0" <?= ($block->isEverythingAllowed() ? '' : 'selected="selected"') ?>><?= /* @escapeNotVerified */ __('Custom') ?></option>
28-
<option value="1" <?= ($block->isEverythingAllowed() ? 'selected="selected"' : '') ?>><?= /* @escapeNotVerified */ __('All') ?></option>
27+
<option value="0" <?= ($block->isEverythingAllowed() ? '' : 'selected="selected"') ?>><?= $block->escapeHtml(__('Custom')) ?></option>
28+
<option value="1" <?= ($block->isEverythingAllowed() ? 'selected="selected"' : '') ?>><?= $block->escapeHtml(__('All')) ?></option>
2929
</select>
3030
</div>
3131
</div>
3232

3333
<div class="field<?php if ($block->isEverythingAllowed()):?> no-display<?php endif?>" data-role="tree-resources-container">
34-
<label class="label"><span><?= /* @escapeNotVerified */ __('Resources') ?></span></label>
34+
<label class="label"><span><?= $block->escapeHtml(__('Resources')) ?></span></label>
3535

3636
<div class="control">
3737
<div class="tree x-tree" data-role="resource-tree" data-mage-init='<?php

app/code/Magento/Marketplace/view/adminhtml/templates/index.phtml

Lines changed: 16 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -8,15 +8,15 @@
88
?>
99

1010
<section class="page-partners">
11-
<h2 class="page-sub-title"><?= /* @escapeNotVerified */ __('Platinum Partners') ?></h2>
11+
<h2 class="page-sub-title"><?= $block->escapeHtml(__('Platinum Partners')) ?></h2>
1212
<p class="partners-description">
13-
<?php /* @escapeNotVerified */
14-
echo __(
13+
<?php
14+
echo $block->escapeHtml(__(
1515
'Representing Magento\'s highest level of partner engagement, Magento Platinum Partners have established themselves as leaders and innovators of key products and services designed to help merchants and brands grow their business. ' .
1616
'Magento reserves the Platinum level for select trusted partners that are committed to offering integrations of commerce features, functions, and tools, as well as back-end systems and operations, to extend and enhance the power of the Magento commerce platform.'
17-
); ?>
17+
)); ?>
1818
</p>
19-
<h3 class="page-sub-sub-title"><?= /* @escapeNotVerified */ __('Featured Platinum Partners') ?></h3>
19+
<h3 class="page-sub-sub-title"><?= $block->escapeHtml(__('Featured Platinum Partners')) ?></h3>
2020
<div data-role="partners-block" class="partners-block">
2121
<div data-role="spinner" class="admin__data-grid-loading-mask">
2222
<div class="spinner">
@@ -29,40 +29,40 @@
2929
<div class="row row-gutter partners-footer">
3030
<div class="col-m-5">
3131
<div class="partners-search">
32-
<h2 class="page-sub-title"><?= /* @escapeNotVerified */ __('Partner search') ?></h2>
32+
<h2 class="page-sub-title"><?= $block->escapeHtml(__('Partner search')) ?></h2>
3333
<p>
34-
<?php /* @escapeNotVerified */
35-
echo __(
34+
<?php
35+
echo $block->escapeHtml(__(
3636
'Magento has a thriving ecosystem of technology partners to help merchants and brands deliver the best possible customer experiences. ' .
3737
'They are recognized as experts in eCommerce, search, email marketing, payments, tax, fraud, optimization and analytics, fulfillment, and more. ' .
3838
'Visit the Magento Partner Directory to see all of our trusted partners.'
39-
); ?>
39+
)); ?>
4040
</p>
4141
<a class="action-secondary" target="_blank"
4242
href="http://partners.magento.com/partner_locator/search.aspx">
43-
<?= /* @escapeNotVerified */ __('More Partners') ?>
43+
<?= $block->escapeHtml(__('More Partners')) ?>
4444
</a>
4545
</div>
4646
</div>
4747
<div class="col-m-3">
4848
<img
4949
class="magento-marketplace-logo"
50-
src="<?php /* @escapeNotVerified */ echo $block
51-
->getViewFileUrl('Magento_Marketplace::partners/images/magento-marketplace.svg');
50+
src="<?php echo $block->escapeUrl($block
51+
->getViewFileUrl('Magento_Marketplace::partners/images/magento-marketplace.svg'));
5252
?>"
5353
alt="Partner"/>
5454
</div>
5555
<div class="col-m-4">
56-
<h2 class="page-sub-title"><?= /* @escapeNotVerified */ __('Magento Marketplace') ?></h2>
56+
<h2 class="page-sub-title"><?= $block->escapeHtml(__('Magento Marketplace')) ?></h2>
5757
<p class="partner-description">
58-
<?php /* @escapeNotVerified */ echo __(
58+
<?php echo $block->escapeHtml(__(
5959
'Extensions and Themes are an essential component of the Magento Ecosystem. ' .
6060
'Please visit the Magento Marketplace to see the latest innovations that developers have created to enhance your Magento Store.'
61-
); ?>
61+
)); ?>
6262
</p>
6363
<a class="action-secondary" target="_blank"
6464
href="https://marketplace.magento.com/">
65-
<?= /* @escapeNotVerified */ __('Visit Magento Marketplaces') ?>
65+
<?= $block->escapeHtml(__('Visit Magento Marketplaces')) ?>
6666
</a>
6767
</div>
6868
</div>

app/code/Magento/Marketplace/view/adminhtml/templates/partners.phtml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -22,17 +22,17 @@ $partners = $block->getPartners();
2222
<?= $block->escapeHtml($partner['description']) ?>
2323
<br />
2424
<a href="<?= $block->escapeHtml($partner['url_page']) ?>" target="_blank">
25-
<?= /* @escapeNotVerified */ __('Read More') ?>
25+
<?= $block->escapeHtml(__('Read More')) ?>
2626
</a>
2727
<br />
2828
<a href="<?= $block->escapeHtml($partner['url_partner_page']) ?>" target="_blank">
29-
<?= /* @escapeNotVerified */ __('Partner Page') ?>
29+
<?= $block->escapeHtml(__('Partner Page')) ?>
3030
</a>
3131
</p>
3232
</div>
3333
<?php endforeach; ?>
3434
<?php else : ?>
3535
<p>
36-
<?= /* @escapeNotVerified */ __('No partners were found') ?>
36+
<?= $block->escapeHtml(__('No partners were found')) ?>
3737
</p>
3838
<?php endif; ?>

app/code/Magento/User/view/adminhtml/templates/admin/forgotpassword.phtml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -9,23 +9,23 @@
99
?>
1010
<form method="post" action="" id="login-form" data-mage-init='{"form": {}, "validation": {}}'>
1111
<fieldset class="admin__fieldset">
12-
<legend class="admin__legend"><span><?= /* @escapeNotVerified */ __('Password Help') ?></span></legend><br/>
13-
<input name="form_key" type="hidden" value="<?= /* @escapeNotVerified */ $block->getFormKey() ?>" />
14-
<p class="admin__field-info"><?= /* @escapeNotVerified */ __('Enter your email address. You will receive an email with a link to reset your password.') ?></p>
12+
<legend class="admin__legend"><span><?= $block->escapeHtml(__('Password Help')) ?></span></legend><br/>
13+
<input name="form_key" type="hidden" value="<?= $block->escapeHtmlAttr($block->getFormKey()) ?>" />
14+
<p class="admin__field-info"><?= $block->escapeHtml(__('Enter your email address. You will receive an email with a link to reset your password.')) ?></p>
1515
<div class="admin__field _required field-email">
16-
<label for="email" class="admin__field-label"><span><?= /* @escapeNotVerified */ __('Email address') ?></span></label>
16+
<label for="email" class="admin__field-label"><span><?= $block->escapeHtml(__('Email address')) ?></span></label>
1717
<div class="admin__field-control">
1818
<input type="text" id="email" name="email" value="" data-validate="{required:true, 'validate-email':true}" class="admin__control-text" />
1919
</div>
2020
</div>
2121
<?= $block->getChildHtml('form.additional.info') ?>
2222
<div class="form-actions">
2323
<div class="actions">
24-
<button class="action-retrieve action-primary" type="submit"><span><?= /* @escapeNotVerified */ __('Retrieve Password') ?></span></button>
24+
<button class="action-retrieve action-primary" type="submit"><span><?= $block->escapeHtml(__('Retrieve Password')) ?></span></button>
2525
</div>
2626
<div class="links">
27-
<a class="action-back" href="<?= /* @escapeNotVerified */ $block->getUrl('adminhtml', ['_nosecret' => true]) ?>">
28-
<?= /* @escapeNotVerified */ __('Back to Sign in') ?>
27+
<a class="action-back" href="<?= $block->escapeUrl($block->getUrl('adminhtml', ['_nosecret' => true])) ?>">
28+
<?= $block->escapeHtml(__('Back to Sign in')) ?>
2929
</a>
3030
</div>
3131
</div>

app/code/Magento/User/view/adminhtml/templates/admin/forgotpassword_url.phtml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,5 +8,5 @@
88

99
?>
1010
<div class="links">
11-
<a class="action-forgotpassword" href="<?= /* @escapeNotVerified */ $this->helper('Magento\Backend\Helper\Data')->getUrl('adminhtml/auth/forgotpassword', ['_nosecret' => true]) ?>"><?= /* @escapeNotVerified */ __('Forgot your password?') ?></a>
11+
<a class="action-forgotpassword" href="<?= $block->escapeUrl($this->helper('Magento\Backend\Helper\Data')->getUrl('adminhtml/auth/forgotpassword', ['_nosecret' => true])) ?>"><?= $block->escapeHtml(__('Forgot your password?')) ?></a>
1212
</div>

app/code/Magento/User/view/adminhtml/templates/admin/resetforgottenpassword.phtml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -8,28 +8,28 @@
88

99
?>
1010

11-
<form method="post" data-mage-init='{"form": {}, "validation": {}}' action="<?= /* @escapeNotVerified */ $block->getUrl('*/auth/resetpasswordpost', ['_query' => ['id' => $block->getUserId(), 'token' => $block->getResetPasswordLinkToken()]]) ?>" id="reset-password-form" autocomplete="off">
11+
<form method="post" data-mage-init='{"form": {}, "validation": {}}' action="<?= $block->escapeUrl($block->getUrl('*/auth/resetpasswordpost', ['_query' => ['id' => $block->getUserId(), 'token' => $block->getResetPasswordLinkToken()]])) ?>" id="reset-password-form" autocomplete="off">
1212
<fieldset class="admin__fieldset">
13-
<legend class="admin__legend"><span><?= /* @escapeNotVerified */ __('Reset a Password') ?></span></legend><br />
14-
<input name="form_key" type="hidden" value="<?= /* @escapeNotVerified */ $block->getFormKey() ?>" />
13+
<legend class="admin__legend"><span><?= $block->escapeHtml(__('Reset a Password')) ?></span></legend><br />
14+
<input name="form_key" type="hidden" value="<?= $block->escapeHtmlAttr($block->getFormKey()) ?>" />
1515
<div class="admin__field _required field-password">
16-
<label class="admin__field-label" for="password"><span><?= /* @escapeNotVerified */ __('New Password') ?></span></label>
16+
<label class="admin__field-label" for="password"><span><?= $block->escapeHtml(__('New Password')) ?></span></label>
1717
<div class="admin__field-control">
1818
<input type="password" class="admin__control-text" data-validate="{required:true, 'validate-admin-password':true}" name="password" id="password" placeholder="new password" autocomplete="off" />
1919
</div>
2020
</div>
2121
<div class="admin__field _required field-confirmation">
22-
<label class="admin__field-label" for="confirmation"><span><?= /* @escapeNotVerified */ __('Confirm New Password') ?></span></label>
22+
<label class="admin__field-label" for="confirmation"><span><?= $block->escapeHtml(__('Confirm New Password')) ?></span></label>
2323
<div class="admin__field-control">
2424
<input type="password" class="admin__control-text" data-validate="{required:true, 'validate-cpassword':true}" name="confirmation" id="confirmation" placeholder="confirm new password" autocomplete="off" />
2525
</div>
2626
</div>
2727
<div class="form-actions">
2828
<div class="actions">
29-
<button type="submit" title="<?= /* @escapeNotVerified */ __('Reset Password') ?>" class="action-reset action-primary"><span><?= /* @escapeNotVerified */ __('Reset Password') ?></span></button>
29+
<button type="submit" title="<?= $block->escapeHtml(__('Reset Password')) ?>" class="action-reset action-primary"><span><?= $block->escapeHtml(__('Reset Password')) ?></span></button>
3030
</div>
3131
<div class="links">
32-
<a class="action-back" href="<?= /* @escapeNotVerified */ $block->getUrl('adminhtml', ['_nosecret' => true]) ?>"><?= /* @escapeNotVerified */ __('Back to Sign in') ?></a>
32+
<a class="action-back" href="<?= $block->escapeUrl($block->getUrl('adminhtml', ['_nosecret' => true])) ?>"><?= $block->escapeHtml(__('Back to Sign in')) ?></a>
3333
</div>
3434
</div>
3535
</fieldset>

0 commit comments

Comments
 (0)