Skip to content

Commit 3fbce83

Browse files
Merge remote-tracking branch '37933/37820-Console-error-in-email-preview' into comprs_jul4
2 parents 92d686d + 6e82ee7 commit 3fbce83

File tree

1 file changed

+10
-6
lines changed

1 file changed

+10
-6
lines changed

app/code/Magento/Email/view/adminhtml/templates/preview/iframeswitcher.phtml

Lines changed: 10 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,28 +1,32 @@
11
<?php
22
/**
3-
* Copyright © Magento, Inc. All rights reserved.
4-
* See COPYING.txt for license details.
3+
* Copyright 2019 Adobe
4+
* All Rights Reserved.
55
*/
66

77
/** @var \Magento\Backend\Block\Page $block */
88
/** @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer */
9+
/** @var \Magento\Framework\Escaper $escaper */
910
?>
1011
<div id="preview" class="cms-revision-preview">
1112
<iframe name="preview_iframe"
1213
id="preview_iframe"
1314
frameborder="0"
14-
title="<?= $block->escapeHtmlAttr(__('Preview')) ?>"
15+
title="<?= $escaper->escapeHtmlAttr(__('Preview')) ?>"
1516
width="100%"
16-
sandbox="allow-same-origin allow-pointer-lock"
17+
sandbox="allow-scripts allow-same-origin allow-pointer-lock"
1718
></iframe>
1819
<form id="preview_form"
19-
action="<?= $block->escapeUrl($block->getUrl('*/*/popup')) ?>"
20+
action="<?= $escaper->escapeUrl($block->getUrl('*/*/popup')) ?>"
2021
method="post"
2122
target="preview_iframe"
2223
>
2324
<input type="hidden" name="form_key" value="<?= /* @noEscape */ $block->getFormKey() ?>" />
2425
<?php foreach ($block->getPreviewFormViewModel()->getFormFields() as $name => $value): ?>
25-
<input type="hidden" name="<?= $block->escapeHtmlAttr($name) ?>" value="<?= $block->escapeHtmlAttr($value) ?>"/>
26+
<input type="hidden"
27+
name="<?= $escaper->escapeHtmlAttr($name) ?>"
28+
value="<?= $escaper->escapeHtmlAttr($value) ?>"
29+
/>
2630
<?php endforeach; ?>
2731
</form>
2832
</div>

0 commit comments

Comments
 (0)