Skip to content

Commit cdb4ebc

Browse files
author
Hwashiang Yu
committed
MC-16877: Eliminate @escapeNotVerified in Catalog Inventory Modules
- Escaped all EscapeNotVerified content in templates
1 parent f9f782b commit cdb4ebc

File tree

3 files changed

+13
-13
lines changed

3 files changed

+13
-13
lines changed

app/code/Magento/CatalogInventory/view/frontend/templates/qtyincrements.phtml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,6 @@
1010
?>
1111
<?php if ($block->getProductQtyIncrements()) : ?>
1212
<div class="product pricing">
13-
<?= /* @escapeNotVerified */ __('%1 is available to buy in increments of %2', $block->getProductName(), $block->getProductQtyIncrements()) ?>
13+
<?= /* @noEscape */ __('%1 is available to buy in increments of %2', $block->escapeHtml($block->getProductName()), $block->escapeHtml($block->getProductQtyIncrements())) ?>
1414
</div>
1515
<?php endif ?>

app/code/Magento/CatalogInventory/view/frontend/templates/stockqty/composite.phtml

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -11,30 +11,30 @@
1111
<?php if ($block->isMsgVisible()) : ?>
1212
<div class="availability only">
1313
<a href="#"
14-
data-mage-init='{"toggleAdvanced": {"selectorsToggleClass": "active", "baseToggleClass": "expanded", "toggleContainers": "#<?= /* @escapeNotVerified */ $block->getDetailsPlaceholderId() ?>"}}'
15-
id="<?= /* @escapeNotVerified */ $block->getPlaceholderId() ?>"
16-
title="<?= /* @escapeNotVerified */ __('Only %1 left', ($block->getStockQtyLeft())) ?>"
14+
data-mage-init='{"toggleAdvanced": {"selectorsToggleClass": "active", "baseToggleClass": "expanded", "toggleContainers": "#<?= $block->escapeHtmlAttr($block->getDetailsPlaceholderId()) ?>"}}'
15+
id="<?= $block->escapeHtmlAttr($block->getPlaceholderId()) ?>"
16+
title="<?= /* @noEscape */ __('Only %1 left', ($block->escapeHtmlAttr($block->getStockQtyLeft()))) ?>"
1717
class="action show">
18-
<?= /* @escapeNotVerified */ __('Only %1 left', "<strong>{$block->getStockQtyLeft()}</strong>") ?>
18+
<?= /* @noEscape */ __('Only %1 left', "<strong>{$block->escapeHtml($block->getStockQtyLeft())}</strong>") ?>
1919
</a>
2020
</div>
21-
<div class="availability only detailed" id="<?= /* @escapeNotVerified */ $block->getDetailsPlaceholderId() ?>">
21+
<div class="availability only detailed" id="<?= $block->escapeHtmlAttr($block->getDetailsPlaceholderId()) ?>">
2222
<div class="table-wrapper">
2323
<table class="data table">
24-
<caption class="table-caption"><?= /* @escapeNotVerified */ __('Product availability') ?></caption>
24+
<caption class="table-caption"><?= $block->escapeHtml(__('Product availability')) ?></caption>
2525
<thead>
2626
<tr>
27-
<th class="col item" scope="col"><?= /* @escapeNotVerified */ __('Product Name') ?></th>
28-
<th class="col qty" scope="col"><?= /* @escapeNotVerified */ __('Qty') ?></th>
27+
<th class="col item" scope="col"><?= $block->escapeHtml(__('Product Name')) ?></th>
28+
<th class="col qty" scope="col"><?= $block->escapeHtml(__('Qty')) ?></th>
2929
</tr>
3030
</thead>
3131
<tbody>
3232
<?php foreach ($block->getChildProducts() as $childProduct) : ?>
3333
<?php $childProductStockQty = $block->getProductStockQty($childProduct); ?>
3434
<?php if ($childProductStockQty > 0) : ?>
3535
<tr>
36-
<td data-th="<?= $block->escapeHtml(__('Product Name')) ?>" class="col item"><?= /* @escapeNotVerified */ $childProduct->getName() ?></td>
37-
<td data-th="<?= $block->escapeHtml(__('Qty')) ?>" class="col qty"><?= /* @escapeNotVerified */ $childProductStockQty ?></td>
36+
<td data-th="<?= $block->escapeHtml(__('Product Name')) ?>" class="col item"><?= $block->escapeHtml($childProduct->getName()) ?></td>
37+
<td data-th="<?= $block->escapeHtml(__('Qty')) ?>" class="col qty"><?= $block->escapeHtml($childProductStockQty) ?></td>
3838
</tr>
3939
<?php endif ?>
4040
<?php endforeach ?>

app/code/Magento/CatalogInventory/view/frontend/templates/stockqty/default.phtml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@
99
*/
1010
?>
1111
<?php if ($block->isMsgVisible()) : ?>
12-
<div class="availability only" title="<?= /* @escapeNotVerified */ __('Only %1 left', ($block->getStockQtyLeft())) ?>">
13-
<?= /* @escapeNotVerified */ __('Only %1 left', "<strong>{$block->getStockQtyLeft()}</strong>") ?>
12+
<div class="availability only" title="<?= /* @noEscape */ __('Only %1 left', ($block->escapeHtmlAttr($block->getStockQtyLeft()))) ?>">
13+
<?= /* @noEscape */ __('Only %1 left', "<strong>{$block->escapeHtml($block->getStockQtyLeft())}</strong>") ?>
1414
</div>
1515
<?php endif ?>

0 commit comments

Comments
 (0)