Skip to content

Commit 14c1b6a

Browse files
author
Oleksandr Gorkun
committed
MAGETWO-55809: Eliminate @escapeNotVerified in Module Backend
1 parent 777eddb commit 14c1b6a

File tree

4 files changed

+8
-8
lines changed

4 files changed

+8
-8
lines changed

app/code/Magento/Backend/view/adminhtml/templates/widget/form/element/gallery.phtml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@
3030
<tr id="<?= $block->getElement()->getHtmlId() ?>_tr_<?= $block->escapeHtmlAttr($image->getValueId()) ?>" class="gallery">
3131
<?php foreach ($block->getValues()->getAttributeBackend()->getImageTypes() as $type) : ?>
3232
<td class="gallery" align="center" style="vertical-align:bottom;">
33-
<a href="<?= $block->escapeUrl($image->setType($type)->getSourceUrl()) ?>" target="_blank" onclick="imagePreview('<?= $block->getElement()->getHtmlId() ?>_image_<?= $block->escapeHtmlAttr($type) ?>_<?= $block->escapeHtmlAttr($image->getValueId()) ?>');return false;">
33+
<a href="<?= $block->escapeUrl($image->setType($type)->getSourceUrl()) ?>" target="_blank" onclick="imagePreview('<?= $block->getElement()->getHtmlId() ?>_image_<?= $block->escapeHtmlAttr($block->escapeJs($type)) ?>_<?= $block->escapeHtmlAttr($block->escapeJs($image->getValueId())) ?>');return false;">
3434
<img id="<?= $block->getElement()->getHtmlId() ?>_image_<?= $block->escapeHtmlAttr($type) ?>_<?= $block->escapeHtmlAttr($image->getValueId()) ?>" src="<?= $block->escapeUrl($image->setType($type)->getSourceUrl()) ?>?<?= /* @noEscape */ time() ?>" alt="<?= $block->escapeHtmlAttr($image->getValue()) ?>" title="<?= $block->escapeHtmlAttr($image->getValue()) ?>" height="25" class="small-image-preview v-middle"/></a><br/>
3535
<input type="file" name="<?= $block->escapeHtmlAttr($block->getElement()->getName()) ?>_<?= $block->escapeHtmlAttr($type) ?>[<?= $block->escapeHtmlAttr($image->getValueId()) ?>]" size="1"></td>
3636
<?php endforeach; ?>

app/code/Magento/Backend/view/adminhtml/templates/widget/grid/column_set.phtml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -94,7 +94,7 @@ $numColumns = count($block->getColumns());
9494
<td data-column="<?= $block->escapeHtmlAttr($_column->getId()) ?>"
9595
class="<?= $block->escapeHtmlAttr($_column->getCssProperty()) ?> <?= /* @noEscape */ $_column->getId() == 'massaction' ? 'data-grid-checkbox-cell': '' ?> <?= ++$i == $numColumns ? 'last' : '' ?>"
9696
>
97-
<?= /* @noEscape */ $_column->hasSubtotalsLabel() ? $_column->getSubtotalsLabel() : $_column->getRowField($block->getSubTotals($_item)) ?>
97+
<?= /* @noEscape */ $_column->hasSubtotalsLabel() ? $block->escapeHtml($_column->getSubtotalsLabel()) : $_column->getRowField($block->getSubTotals($_item)) ?>
9898
</td>
9999
<?php endforeach; ?>
100100
</tr>
@@ -138,7 +138,7 @@ $numColumns = count($block->getColumns());
138138
<th data-column="<?= $block->escapeHtmlAttr($_column->getId()) ?>"
139139
class="<?= $block->escapeHtmlAttr($_column->getCssProperty()) ?>"
140140
>
141-
<?= /* @noEscape */ ($_column->hasTotalsLabel()) ? $_column->getTotalsLabel() : $_column->getRowField($block->getTotals()) ?>
141+
<?= /* @noEscape */ ($_column->hasTotalsLabel()) ? $block->escapeHtml($_column->getTotalsLabel()) : $_column->getRowField($block->getTotals()) ?>
142142
</th>
143143
<?php endforeach; ?>
144144
</tr>

app/code/Magento/Backend/view/adminhtml/templates/widget/grid/extended.phtml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -114,7 +114,7 @@ $numColumns = count($block->getColumns());
114114
</label>
115115
<?php if ($_curPage < $_lastPage) : ?>
116116
<button type="button"
117-
title="<?= $block->escapeHtml(__('Next page')) ?>"
117+
title="<?= $block->escapeHtmlAttr(__('Next page')) ?>"
118118
class="action-next"
119119
onclick="<?= /* @noEscape */ $block->getJsObjectName() ?>.setPage('<?= /* @noEscape */ ($_curPage + 1) ?>');return false;">
120120
<span><?= $block->escapeHtml(__('Next page')) ?></span>
@@ -168,7 +168,7 @@ $numColumns = count($block->getColumns());
168168
<tr class="totals">
169169
<?php foreach ($block->getColumns() as $_column) : ?>
170170
<th class="<?= $block->escapeHtmlAttr($_column->getCssProperty()) ?>">
171-
<?= /* @noEscape */ ($_column->hasTotalsLabel()) ? $_column->getTotalsLabel() : $_column->getRowField($_column->getGrid()->getTotals()) ?>
171+
<?= /* @noEscape */ ($_column->hasTotalsLabel()) ? $block->escapeHtml($_column->getTotalsLabel()) : $_column->getRowField($_column->getGrid()->getTotals()) ?>
172172
</th>
173173
<?php endforeach; ?>
174174
</tr>
@@ -218,7 +218,7 @@ $numColumns = count($block->getColumns());
218218
foreach ($block->getSubTotalColumns() as $_column) : ?>
219219
<td class="<?= $block->escapeHtmlAttr($_column->getCssProperty()) ?>
220220
<?= /* @noEscape */ $_column->getId() == 'massaction' ? 'data-grid-checkbox-cell': '' ?>">
221-
<?= /* @noEscape */ $_column->hasSubtotalsLabel() ? $_column->getSubtotalsLabel() : $_column->getRowField($block->getSubTotalItem($_item)) ?>
221+
<?= /* @noEscape */ $_column->hasSubtotalsLabel() ? $block->escapeHtml($_column->getSubtotalsLabel()) : $_column->getRowField($block->getSubTotalItem($_item)) ?>
222222
</td>
223223
<?php endforeach; ?>
224224
</tr>

app/code/Magento/Backend/view/adminhtml/templates/widget/grid/massaction.phtml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@
4444
class="action-select-multiselect _disabled"
4545
disabled="disabled"
4646
data-menu="grid-mass-select">
47-
<optgroup label="<?= $block->escapeHtml(__('Mass Actions')) ?>">
47+
<optgroup label="<?= $block->escapeHtmlAttr(__('Mass Actions')) ?>">
4848
<option disabled selected></option>
4949
<?php if ($block->getUseSelectAll()) :?>
5050
<option value="selectAll">
@@ -93,7 +93,7 @@
9393
});
9494
});
9595
<?php if (!$block->getParentBlock()->canDisplayContainer()) : ?>
96-
<?= $block->escapeJs($block->getJsObjectName()) ?>.setGridIds('<?= /* @noEscape */ $block->getGridIdsJson() ?>');
96+
<?= $block->escapeJs($block->getJsObjectName()) ?>.setGridIds('<?= $block->escapeJs($block->getGridIdsJson()) ?>');
9797
<?php endif; ?>
9898
</script>
9999
</div>

0 commit comments

Comments
 (0)