Skip to content

Commit b0683e0

Browse files
committed
order metadata xss
1 parent 439f6e0 commit b0683e0

File tree

1 file changed

+5
-5
lines changed

1 file changed

+5
-5
lines changed

src/elements/Order.php

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3399,24 +3399,24 @@ public function getMetadata(): array
33993399
$metadata = [];
34003400

34013401
if ($this->isCompleted) {
3402-
$metadata[Craft::t('commerce', 'Reference')] = $this->reference;
3402+
$metadata[Craft::t('commerce', 'Reference')] = Html::encode($this->reference);
34033403
$metadata[Craft::t('commerce', 'Date Ordered')] = Craft::$app->getFormatter()->asDatetime($this->dateOrdered, 'short');
34043404
}
34053405

3406-
$metadata[Craft::t('commerce', 'Coupon Code')] = $this->couponCode;
3406+
$metadata[Craft::t('commerce', 'Coupon Code')] = Html::encode($this->couponCode);
34073407

34083408
$orderSite = $this->getOrderSite();
3409-
$metadata[Craft::t('commerce', 'Order Site')] = $orderSite?->getName() ?? '';
3409+
$metadata[Craft::t('commerce', 'Order Site')] = Html::encode($orderSite?->getName()) ?? '';
34103410

34113411
$shippingMethod = $this->getShippingMethod();
3412-
$metadata[Craft::t('commerce', 'Shipping Method')] = $shippingMethod?->getName() ?? '';
3412+
$metadata[Craft::t('commerce', 'Shipping Method')] = Html::encode($shippingMethod?->getName()) ?? '';
34133413

34143414
$metadata[Craft::t('app', 'ID')] = $this->id;
34153415
$metadata[Craft::t('commerce', 'Short Number')] = $this->getShortNumber();
34163416
$metadata[Craft::t('commerce', 'Paid Status')] = $this->getPaidStatusHtml();
34173417
$metadata[Craft::t('commerce', 'Total Price')] = $this->totalPriceAsCurrency;
34183418
$metadata[Craft::t('commerce', 'Paid Amount')] = $this->totalPaidAsCurrency;
3419-
$metadata[Craft::t('commerce', 'Origin')] = $this->origin;
3419+
$metadata[Craft::t('commerce', 'Origin')] = Html::encode($this->origin);
34203420

34213421
return array_merge($metadata, parent::getMetadata());
34223422
}

0 commit comments

Comments
 (0)