Skip to content

Commit 07358f2

Browse files
author
Hwashiang Yu
committed
MAGETWO-56444: UI-Related Modules Template Update
- Resolved incorrectly escaped templates
1 parent 3e109c7 commit 07358f2

File tree

5 files changed

+9
-9
lines changed

5 files changed

+9
-9
lines changed

app/code/Magento/Theme/view/adminhtml/templates/browser/content/uploader.phtml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@
1111
<span class="fileinput-button form-buttons">
1212
<span><?= $block->escapeHtml(__('Browse Files')) ?></span>
1313
<input id="fileupload" type="file" name="<?= $block->escapeHtmlAttr($block->getConfig()->getFileField()) ?>"
14-
data-url="<?= $block->escapeHtmlAttr($block->escapeUrl($block->getConfig()->getUrl())) ?>" multiple>
14+
data-url="<?= $block->escapeUrl($block->getConfig()->getUrl()) ?>" multiple>
1515
</span>
1616
<div class="clear"></div>
1717
<script id="<?= $block->getHtmlId() ?>-template" type="text/x-magento-template">

app/code/Magento/Theme/view/frontend/templates/html/pager.phtml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -105,7 +105,7 @@
105105
<?php if (!$block->isLastPage()): ?>
106106
<li class="item pages-item-next">
107107
<?php $text = $block->getAnchorTextForNext() ? $block->getAnchorTextForNext() : '';?>
108-
<a class="<?= $block->escapeHtmlAttr($text ? 'link ' : 'action ') ?> next"
108+
<a class="<?= /* @noEscape */ $text ? 'link ' : 'action ' ?> next"
109109
href="<?= $block->escapeUrl($block->getNextPageUrl()) ?>"
110110
title="<?= $block->escapeHtmlAttr($text ? $text : __('Next')) ?>">
111111
<span class="label"><?= $block->escapeHtml(__('Page')) ?></span>

app/code/Magento/Theme/view/frontend/templates/js/cookie.phtml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,10 +16,10 @@
1616
"*": {
1717
"mage/cookies": {
1818
"expires": null,
19-
"path": "<?= /* @noEscape */ $block->getPath() ?>",
20-
"domain": "<?= /* @noEscape */ $block->getDomain() ?>",
19+
"path": "<?= $block->escapeJs($block->getPath()) ?>",
20+
"domain": "<?= $block->escapeJs($block->getDomain()) ?>",
2121
"secure": false,
22-
"lifetime": "<?= /* @noEscape */ $block->getLifetime() ?>"
22+
"lifetime": "<?= $block->escapeJs($block->getLifetime()) ?>"
2323
}
2424
}
2525
}

app/code/Magento/Theme/view/frontend/templates/link.phtml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,8 +12,8 @@
1212
?>
1313
<?php if (!$block->getIsDisabled()) : ?>
1414
<li>
15-
<a href="<?= $block->escapeHtml($block->getHref()) ?>"
16-
<?php if ($title = $block->getTitle()) : ?> title="<?= $block->escapeHtml(__($title)) ?>"<?php endif;?>>
15+
<a href="<?= $block->escapeUrl($block->getHref()) ?>"
16+
<?php if ($title = $block->getTitle()) : ?> title="<?= $block->escapeHtmlAttr(__($title)) ?>"<?php endif;?>>
1717
<?= $block->escapeHtml(__($block->getLabel())) ?>
1818
</a>
1919
</li>

app/code/Magento/Theme/view/frontend/templates/page/js/require_js.phtml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,8 +5,8 @@
55
*/
66
?>
77
<script>
8-
var BASE_URL = '<?= $block->escapeJs($block->escapeUrl($block->getBaseUrl())) ?>';
8+
var BASE_URL = '<?= $block->escapeUrl($block->getBaseUrl()) ?>';
99
var require = {
10-
"baseUrl": "<?= $block->escapeJs($block->escapeUrl($block->getViewFileUrl('/'))) ?>"
10+
"baseUrl": "<?= $block->escapeUrl($block->getViewFileUrl('/')) ?>"
1111
};
1212
</script>

0 commit comments

Comments
 (0)