diff --git a/app/code/Magento/Reports/Block/Adminhtml/Grid.php b/app/code/Magento/Reports/Block/Adminhtml/Grid.php index eade7250f6123..375d532cee823 100644 --- a/app/code/Magento/Reports/Block/Adminhtml/Grid.php +++ b/app/code/Magento/Reports/Block/Adminhtml/Grid.php @@ -370,7 +370,7 @@ public function getFilter($name) if (isset($this->_filters[$name])) { return $this->_filters[$name]; } else { - return $this->getRequest()->getParam($name) ? $this->escapeHtml($this->getRequest()->getParam($name)) : ''; + return $this->getRequest()->getParam($name) ? $this->_escaper->escapeHtml($this->getRequest()->getParam($name)) : ''; } } diff --git a/app/code/Magento/Reports/view/adminhtml/templates/grid.phtml b/app/code/Magento/Reports/view/adminhtml/templates/grid.phtml index 4f6e3c4a9a02b..4e95594c255c3 100644 --- a/app/code/Magento/Reports/view/adminhtml/templates/grid.phtml +++ b/app/code/Magento/Reports/view/adminhtml/templates/grid.phtml @@ -8,11 +8,13 @@ /** * @var $block \Magento\Reports\Block\Adminhtml\Grid * @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer + * @var \Magento\Framework\Escaper $escaper + */ ?> getCollection()): ?> canDisplayContainer()): ?> -
+
getLayout()->getMessagesBlock()->getGroupedHtml() ?> @@ -21,47 +23,47 @@
getDateFilterVisibility()): ?>
+ id="escapeHtmlAttr($block->getSuffixId('period_date_range')) ?>"> - - + value="escapeHtmlAttr($block->getFilter('report_from')) ?>"> + - - + value="escapeHtmlAttr($block->getFilter('report_to')) ?>"/> + - @@ -74,14 +76,14 @@ "mage/calendar" ], function($){ - $("#{$block->escapeJs($block->getSuffixId('period_date_range'))}").dateRange({ - dateFormat:"{$block->escapeJs($block->getDateFormat())}", - buttonText:"{$block->escapeJs(__('Select Date'))}", + $("#{$escaper->escapeJs($block->getSuffixId('period_date_range'))}").dateRange({ + dateFormat:"{$escaper->escapeJs($block->getDateFormat())}", + buttonText:"{$escaper->escapeJs(__('Select Date'))}", from:{ - id:"{$block->escapeJs($block->getSuffixId('period_date_from'))}" + id:"{$escaper->escapeJs($block->getSuffixId('period_date_from'))}" }, to:{ - id:"{$block->escapeJs($block->getSuffixId('period_date_to'))}" + id:"{$escaper->escapeJs($block->getSuffixId('period_date_to'))}" } }); }); @@ -98,7 +100,7 @@ script;
- +
getChildHtml('grid.columnSet') ?>
@@ -106,7 +108,7 @@ script; canDisplayContainer()): ?> getUseAjax()): - $useAjax = $block->escapeJs($block->getUseAjax()); + $useAjax = $escaper->escapeJs($block->getUseAjax()); endif; $scriptString = <<