File tree Expand file tree Collapse file tree 1 file changed +10
-6
lines changed
app/code/Magento/Email/view/adminhtml/templates/preview Expand file tree Collapse file tree 1 file changed +10
-6
lines changed Original file line number Diff line number Diff line change 1
1
<?php
2
2
/**
3
- * Copyright © Magento, Inc. All rights reserved.
4
- * See COPYING.txt for license details .
3
+ * Copyright 2019 Adobe
4
+ * All Rights Reserved .
5
5
*/
6
6
7
7
/** @var \Magento\Backend\Block\Page $block */
8
8
/** @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer */
9
+ /** @var \Magento\Framework\Escaper $escaper */
9
10
?>
10
11
<div id="preview" class="cms-revision-preview">
11
12
<iframe name="preview_iframe"
12
13
id="preview_iframe"
13
14
frameborder="0"
14
- title="<?= $ block ->escapeHtmlAttr (__ ('Preview ' )) ?> "
15
+ title="<?= $ escaper ->escapeHtmlAttr (__ ('Preview ' )) ?> "
15
16
width="100%"
16
- sandbox="allow-same-origin allow-pointer-lock"
17
+ sandbox="allow-scripts allow- same-origin allow-pointer-lock"
17
18
></iframe>
18
19
<form id="preview_form"
19
- action="<?= $ block ->escapeUrl ($ block ->getUrl ('*/*/popup ' )) ?> "
20
+ action="<?= $ escaper ->escapeUrl ($ block ->getUrl ('*/*/popup ' )) ?> "
20
21
method="post"
21
22
target="preview_iframe"
22
23
>
23
24
<input type="hidden" name="form_key" value="<?= /* @noEscape */ $ block ->getFormKey () ?> " />
24
25
<?php foreach ($ block ->getPreviewFormViewModel ()->getFormFields () as $ name => $ value ): ?>
25
- <input type="hidden" name="<?= $ block ->escapeHtmlAttr ($ name ) ?> " value="<?= $ block ->escapeHtmlAttr ($ value ) ?> "/>
26
+ <input type="hidden"
27
+ name="<?= $ escaper ->escapeHtmlAttr ($ name ) ?> "
28
+ value="<?= $ escaper ->escapeHtmlAttr ($ value ) ?> "
29
+ />
26
30
<?php endforeach ; ?>
27
31
</form>
28
32
</div>
You can’t perform that action at this time.
0 commit comments