From c0626d89670401bceb4b3f03def72100c0b7156f Mon Sep 17 00:00:00 2001 From: sergey Date: Sat, 16 Jan 2021 15:09:10 +0200 Subject: [PATCH] Magento_Sales: Avoid using deprecated escape* methods from AbstractBlock --- .../Block/Adminhtml/Order/Create/Comment.php | 2 +- .../Adminhtml/Order/Create/Form/Address.php | 2 +- .../Block/Adminhtml/Order/Create/Header.php | 2 +- .../Order/Create/Totals/Shipping.php | 4 +- .../Sales/Block/Adminhtml/Order/View/Info.php | 4 +- .../Adminhtml/Order/View/Tab/History.php | 2 +- .../Adminhtml/Reorder/Renderer/Action.php | 2 +- .../Block/Adminhtml/Transactions/Detail.php | 12 +-- .../Block/Order/Email/Items/DefaultItems.php | 4 +- .../Order/Email/Items/Order/DefaultOrder.php | 4 +- .../Order/Item/Renderer/DefaultRenderer.php | 2 +- .../Block/Status/Grid/Column/Unassign.php | 2 +- .../templates/items/column/name.phtml | 15 ++-- .../templates/items/column/qty.phtml | 13 +-- .../templates/items/renderer/default.phtml | 13 +-- .../templates/order/address/form.phtml | 8 +- .../templates/order/comments/view.phtml | 21 +++-- .../templates/order/create/abstract.phtml | 6 +- .../order/create/billing/method/form.phtml | 29 ++++--- .../templates/order/create/comment.phtml | 5 +- .../templates/order/create/coupons/form.phtml | 9 +- .../templates/order/create/data.phtml | 23 ++--- .../templates/order/create/form.phtml | 11 ++- .../templates/order/create/form/account.phtml | 5 +- .../templates/order/create/form/address.phtml | 45 +++++----- .../templates/order/create/giftmessage.phtml | 5 +- .../templates/order/create/items.phtml | 7 +- .../templates/order/create/items/grid.phtml | 63 +++++++------- .../adminhtml/templates/order/create/js.phtml | 9 +- .../order/create/newsletter/form.phtml | 7 +- .../order/create/shipping/method/form.phtml | 31 +++---- .../templates/order/create/sidebar.phtml | 13 +-- .../order/create/sidebar/items.phtml | 59 ++++++------- .../templates/order/create/store/select.phtml | 13 +-- .../templates/order/create/totals.phtml | 7 +- .../order/create/totals/default.phtml | 15 ++-- .../order/create/totals/grandtotal.phtml | 25 +++--- .../order/create/totals/shipping.phtml | 33 ++++---- .../order/create/totals/subtotal.phtml | 25 +++--- .../templates/order/create/totals/tax.phtml | 37 +++++---- .../order/creditmemo/create/form.phtml | 21 +++-- .../order/creditmemo/create/items.phtml | 41 ++++----- .../create/totals/adjustments.phtml | 13 +-- .../order/creditmemo/view/form.phtml | 29 ++++--- .../order/creditmemo/view/items.phtml | 21 +++-- .../adminhtml/templates/order/details.phtml | 37 +++++---- .../templates/order/giftoptions.phtml | 6 +- .../templates/order/invoice/create/form.phtml | 25 +++--- .../order/invoice/create/items.phtml | 47 ++++++----- .../templates/order/invoice/view/form.phtml | 27 +++--- .../templates/order/invoice/view/items.phtml | 19 +++-- .../adminhtml/templates/order/totalbar.phtml | 7 +- .../adminhtml/templates/order/totals.phtml | 15 ++-- .../templates/order/totals/discount.phtml | 8 +- .../templates/order/totals/due.phtml | 7 +- .../templates/order/totals/grand.phtml | 9 +- .../templates/order/totals/item.phtml | 8 +- .../templates/order/totals/paid.phtml | 6 +- .../templates/order/totals/refunded.phtml | 6 +- .../templates/order/totals/shipping.phtml | 6 +- .../templates/order/totals/tax.phtml | 13 +-- .../templates/order/view/giftmessage.phtml | 39 +++++---- .../templates/order/view/history.phtml | 31 +++---- .../adminhtml/templates/order/view/info.phtml | 83 ++++++++++--------- .../templates/order/view/items.phtml | 3 +- .../templates/order/view/tab/history.phtml | 17 ++-- .../templates/order/view/tab/info.phtml | 19 +++-- .../templates/rss/order/grid/link.phtml | 7 +- .../templates/transactions/detail.phtml | 25 +++--- .../templates/email/creditmemo/items.phtml | 9 +- .../templates/email/invoice/items.phtml | 9 +- .../view/frontend/templates/email/items.phtml | 21 +++-- .../email/items/creditmemo/default.phtml | 13 +-- .../email/items/invoice/default.phtml | 14 ++-- .../templates/email/items/order/default.phtml | 25 +++--- .../email/items/shipment/default.phtml | 13 +-- .../templates/email/shipment/items.phtml | 7 +- .../templates/email/shipment/track.phtml | 17 ++-- .../view/frontend/templates/guest/form.phtml | 27 +++--- .../frontend/templates/items/price/row.phtml | 7 +- .../frontend/templates/items/price/unit.phtml | 7 +- .../frontend/templates/order/comments.phtml | 5 +- .../frontend/templates/order/creditmemo.phtml | 9 +- .../templates/order/creditmemo/items.phtml | 30 ++++--- .../creditmemo/items/renderer/default.phtml | 39 +++++---- .../frontend/templates/order/history.phtml | 35 ++++---- .../view/frontend/templates/order/info.phtml | 21 +++-- .../templates/order/info/buttons.phtml | 9 +- .../templates/order/info/buttons/rss.phtml | 9 +- .../frontend/templates/order/invoice.phtml | 9 +- .../templates/order/invoice/items.phtml | 26 +++--- .../invoice/items/renderer/default.phtml | 31 ++++--- .../view/frontend/templates/order/items.phtml | 29 ++++--- .../order/items/renderer/default.phtml | 37 +++++---- .../templates/order/order_comments.phtml | 11 ++- .../frontend/templates/order/order_date.phtml | 6 +- .../templates/order/order_status.phtml | 9 +- .../templates/order/print/creditmemo.phtml | 34 ++++---- .../templates/order/print/invoice.phtml | 32 +++---- .../frontend/templates/order/recent.phtml | 45 +++++----- .../shipment/items/renderer/default.phtml | 24 +++--- .../frontend/templates/order/totals.phtml | 9 +- .../view/frontend/templates/order/view.phtml | 19 +++-- .../frontend/templates/reorder/sidebar.phtml | 21 ++--- .../templates/widget/guest/form.phtml | 23 ++--- 105 files changed, 1073 insertions(+), 807 deletions(-) diff --git a/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Comment.php b/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Comment.php index 9a8bac6ea8f80..89dbc8b974817 100644 --- a/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Comment.php +++ b/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Comment.php @@ -48,6 +48,6 @@ public function getHeaderText() */ public function getCommentNote() { - return $this->escapeHtml($this->getQuote()->getCustomerNote()); + return $this->_escaper->escapeHtml($this->getQuote()->getCustomerNote()); } } diff --git a/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Form/Address.php b/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Form/Address.php index bcdeb4e7d67de..ac09fbe7801d5 100644 --- a/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Form/Address.php +++ b/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Form/Address.php @@ -387,7 +387,7 @@ public function getAddressAsString(\Magento\Customer\Api\Data\AddressInterface $ $result = $formatTypeRenderer->renderArray($this->addressMapper->toFlatArray($address)); } - return $this->escapeHtml($result); + return $this->_escaper->escapeHtml($result); } /** diff --git a/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Header.php b/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Header.php index 3fe2e0f5bc6aa..217f8e7647973 100644 --- a/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Header.php +++ b/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Header.php @@ -63,7 +63,7 @@ protected function _toHtml() return __('Edit Order #%1', $this->_getSession()->getOrder()->getIncrementId()); } $out = $this->_getCreateOrderTitle(); - return $this->escapeHtml($out); + return $this->_escaper->escapeHtml($out); } /** diff --git a/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Totals/Shipping.php b/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Totals/Shipping.php index 34a9ed8070e26..58bcaa1cf490a 100644 --- a/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Totals/Shipping.php +++ b/app/code/Magento/Sales/Block/Adminhtml/Order/Create/Totals/Shipping.php @@ -102,7 +102,7 @@ public function getIncludeTaxLabel() { return __( 'Shipping Incl. Tax (%1)', - $this->escapeHtml($this->getQuote()->getShippingAddress()->getShippingDescription()) + $this->_escaper->escapeHtml($this->getQuote()->getShippingAddress()->getShippingDescription()) ); } @@ -115,7 +115,7 @@ public function getExcludeTaxLabel() { return __( 'Shipping Excl. Tax (%1)', - $this->escapeHtml($this->getQuote()->getShippingAddress()->getShippingDescription()) + $this->_escaper->escapeHtml($this->getQuote()->getShippingAddress()->getShippingDescription()) ); } } diff --git a/app/code/Magento/Sales/Block/Adminhtml/Order/View/Info.php b/app/code/Magento/Sales/Block/Adminhtml/Order/View/Info.php index 22f61d3583faa..9b65aa6823edc 100644 --- a/app/code/Magento/Sales/Block/Adminhtml/Order/View/Info.php +++ b/app/code/Magento/Sales/Block/Adminhtml/Order/View/Info.php @@ -202,7 +202,7 @@ public function getCustomerAccountData() $sortOrder = $this->_prepareAccountDataSortOrder($accountData, $sortOrder); $accountData[$sortOrder] = [ 'label' => $attribute->getFrontendLabel(), - 'value' => $this->escapeHtml($value, ['br']), + 'value' => $this->_escaper->escapeHtml($value, ['br']), ]; } } @@ -225,7 +225,7 @@ public function getAddressEditLink($address, $label = '') $label = __('Edit'); } $url = $this->getUrl('sales/order/address', ['address_id' => $address->getId()]); - return '' . $this->escapeHtml($label) . ''; + return '' . $this->_escaper->escapeHtml($label) . ''; } return ''; diff --git a/app/code/Magento/Sales/Block/Adminhtml/Order/View/Tab/History.php b/app/code/Magento/Sales/Block/Adminhtml/Order/View/Tab/History.php index 0972d74314246..67704a5527901 100644 --- a/app/code/Magento/Sales/Block/Adminhtml/Order/View/Tab/History.php +++ b/app/code/Magento/Sales/Block/Adminhtml/Order/View/Tab/History.php @@ -173,7 +173,7 @@ public function getItemCreatedAt(array $item, $dateType = 'date', $format = \Int */ public function getItemTitle(array $item) { - return isset($item['title']) ? $this->escapeHtml($item['title']) : ''; + return isset($item['title']) ? $this->_escaper->escapeHtml($item['title']) : ''; } /** diff --git a/app/code/Magento/Sales/Block/Adminhtml/Reorder/Renderer/Action.php b/app/code/Magento/Sales/Block/Adminhtml/Reorder/Renderer/Action.php index 566ea1214d91f..47452db3d277d 100644 --- a/app/code/Magento/Sales/Block/Adminhtml/Reorder/Renderer/Action.php +++ b/app/code/Magento/Sales/Block/Adminhtml/Reorder/Renderer/Action.php @@ -74,7 +74,7 @@ public function render(\Magento\Framework\DataObject $row) protected function _getEscapedValue($value) { // phpcs:ignore Magento2.Functions.DiscouragedFunction - return addcslashes($this->escapeHtml($value), '\\\''); + return addcslashes($this->_escaper->escapeHtml($value), '\\\''); } /** diff --git a/app/code/Magento/Sales/Block/Adminhtml/Transactions/Detail.php b/app/code/Magento/Sales/Block/Adminhtml/Transactions/Detail.php index 78756eb03c94a..455b5378af16b 100644 --- a/app/code/Magento/Sales/Block/Adminhtml/Transactions/Detail.php +++ b/app/code/Magento/Sales/Block/Adminhtml/Transactions/Detail.php @@ -126,17 +126,17 @@ protected function _toHtml() )); $this->setParentTxnIdUrlHtml( - $this->escapeHtml($this->getUrl('sales/transactions/view', ['txn_id' => $this->_txn->getParentId()])) + $this->_escaper->escapeHtml($this->getUrl('sales/transactions/view', ['txn_id' => $this->_txn->getParentId()])) ); - $this->setParentTxnIdHtml($this->escapeHtml($this->_txn->getParentTxnId())); + $this->setParentTxnIdHtml($this->_escaper->escapeHtml($this->_txn->getParentTxnId())); - $this->setOrderIncrementIdHtml($this->escapeHtml($this->_txn->getOrder()->getIncrementId())); + $this->setOrderIncrementIdHtml($this->_escaper->escapeHtml($this->_txn->getOrder()->getIncrementId())); - $this->setTxnTypeHtml($this->escapeHtml(__($this->_txn->getTxnType()))); + $this->setTxnTypeHtml($this->_escaper->escapeHtml(__($this->_txn->getTxnType()))); $this->setOrderIdUrlHtml( - $this->escapeHtml($this->getUrl('sales/order/view', ['order_id' => $this->_txn->getOrderId()])) + $this->_escaper->escapeHtml($this->getUrl('sales/order/view', ['order_id' => $this->_txn->getOrderId()])) ); $this->setIsClosedHtml($this->_txn->getIsClosed() ? __('Yes') : __('No')); @@ -150,7 +150,7 @@ protected function _toHtml() ) : __( 'N/A' ); - $this->setCreatedAtHtml($this->escapeHtml($createdAt)); + $this->setCreatedAtHtml($this->_escaper->escapeHtml($createdAt)); return parent::_toHtml(); } diff --git a/app/code/Magento/Sales/Block/Order/Email/Items/DefaultItems.php b/app/code/Magento/Sales/Block/Order/Email/Items/DefaultItems.php index 57fc0441fe830..685abdfdfb4e0 100644 --- a/app/code/Magento/Sales/Block/Order/Email/Items/DefaultItems.php +++ b/app/code/Magento/Sales/Block/Order/Email/Items/DefaultItems.php @@ -67,13 +67,13 @@ public function getValueHtml($value) return sprintf( '%d', $value['qty'] - ) . ' x ' . $this->escapeHtml( + ) . ' x ' . $this->_escaper->escapeHtml( $value['title'] ) . " " . $this->getItem()->getOrder()->formatPrice( $value['price'] ); } else { - return $this->escapeHtml($value); + return $this->_escaper->escapeHtml($value); } } diff --git a/app/code/Magento/Sales/Block/Order/Email/Items/Order/DefaultOrder.php b/app/code/Magento/Sales/Block/Order/Email/Items/Order/DefaultOrder.php index cb9c7315244ac..14c8718d2eeb9 100644 --- a/app/code/Magento/Sales/Block/Order/Email/Items/Order/DefaultOrder.php +++ b/app/code/Magento/Sales/Block/Order/Email/Items/Order/DefaultOrder.php @@ -60,10 +60,10 @@ public function getValueHtml($value) { if (is_array($value)) { return sprintf('%d', $value['qty']) - . ' x ' . $this->escapeHtml($value['title']) + . ' x ' . $this->_escaper->escapeHtml($value['title']) . " " . $this->getItem()->getOrder()->formatPrice($value['price']); } else { - return $this->escapeHtml($value); + return $this->_escaper->escapeHtml($value); } } diff --git a/app/code/Magento/Sales/Block/Order/Item/Renderer/DefaultRenderer.php b/app/code/Magento/Sales/Block/Order/Item/Renderer/DefaultRenderer.php index 010878559c2f0..640be3f40113a 100644 --- a/app/code/Magento/Sales/Block/Order/Item/Renderer/DefaultRenderer.php +++ b/app/code/Magento/Sales/Block/Order/Item/Renderer/DefaultRenderer.php @@ -223,7 +223,7 @@ public function getProductAdditionalInformationBlock() */ public function prepareSku($sku) { - return $this->escapeHtml($this->string->splitInjection($sku)); + return $this->_escaper->escapeHtml($this->string->splitInjection($sku)); } /** diff --git a/app/code/Magento/Sales/Block/Status/Grid/Column/Unassign.php b/app/code/Magento/Sales/Block/Status/Grid/Column/Unassign.php index f989deb0ae7c0..c591744d0ac2f 100644 --- a/app/code/Magento/Sales/Block/Status/Grid/Column/Unassign.php +++ b/app/code/Magento/Sales/Block/Status/Grid/Column/Unassign.php @@ -62,7 +62,7 @@ public function decorateAction($value, $row, $column, $isExport) $url = $this->getUrl('*/*/unassign'); $label = __('Unassign'); $cell = 'getId() ?>_title" class="product-title"> - escapeHtml($_item->getName()) ?> + escapeHtml($_item->getName()) ?>
- escapeHtml(__('SKU'))?>: - ', $catalogHelper->splitSku($block->escapeHtml($block->getSku()))) ?> + escapeHtml(__('SKU'))?>: + ', $catalogHelper->splitSku($escaper->escapeHtml($block->getSku()))) ?>
getOrderOptions()): ?>
getOrderOptions() as $_option): ?> -
escapeHtml($_option['label']) ?>:
+
escapeHtml($_option['label']) ?>:
getCustomizedOptionValue($_option) ?> @@ -37,11 +38,11 @@ $catalogHelper = $block->getData('catalogHelper'); getFormattedOption($_option['value']); ?> - escapeHtml($_option['value'], ['a', 'br']) ?> + escapeHtml($_option['value'], ['a', 'br']) ?> ... - escapeHtml($_option['remainder'], ['a']) ?> + escapeHtml($_option['remainder'], ['a']) ?>
- escapeHtml($_item->getDescription()) ?> + escapeHtml($_item->getDescription()) ?> diff --git a/app/code/Magento/Sales/view/adminhtml/templates/items/column/qty.phtml b/app/code/Magento/Sales/view/adminhtml/templates/items/column/qty.phtml index be630c3debc33..9be7b59970b8f 100644 --- a/app/code/Magento/Sales/view/adminhtml/templates/items/column/qty.phtml +++ b/app/code/Magento/Sales/view/adminhtml/templates/items/column/qty.phtml @@ -3,38 +3,41 @@ * Copyright © Magento, Inc. All rights reserved. * See COPYING.txt for license details. */ +/** + * @var \Magento\Framework\Escaper $escaper + */ ?> getItem()) : ?> - + getQtyInvoiced()) : ?> - + getQtyShipped()) : ?> - + getQtyRefunded()) : ?> - + getQtyCanceled()) : ?> - + diff --git a/app/code/Magento/Sales/view/adminhtml/templates/items/renderer/default.phtml b/app/code/Magento/Sales/view/adminhtml/templates/items/renderer/default.phtml index 0c5b276bf382b..9dd4d8a4df25f 100644 --- a/app/code/Magento/Sales/view/adminhtml/templates/items/renderer/default.phtml +++ b/app/code/Magento/Sales/view/adminhtml/templates/items/renderer/default.phtml @@ -5,22 +5,25 @@ */ // phpcs:disable Magento2.Templates.ThisInTemplate +/** + * @var \Magento\Framework\Escaper $escaper + */ ?> -escapeHtml($block->getItem()->getName()) ?> -
escapeHtml(__('SKU')) ?>: ', $this->helper(\Magento\Catalog\Helper\Data::class)->splitSku($block->escapeHtml($block->getItem()->getSku()))) ?>
+escapeHtml($block->getItem()->getName()) ?> +
escapeHtml(__('SKU')) ?>: ', $this->helper(\Magento\Catalog\Helper\Data::class)->splitSku($escaper->escapeHtml($block->getItem()->getSku()))) ?>
getOrderOptions()) : ?> -escapeHtml($block->getItem()->getDescription()) ?> +escapeHtml($block->getItem()->getDescription()) ?> diff --git a/app/code/Magento/Sales/view/adminhtml/templates/order/address/form.phtml b/app/code/Magento/Sales/view/adminhtml/templates/order/address/form.phtml index 0cc23056b3c2f..61d0eb476d09b 100644 --- a/app/code/Magento/Sales/view/adminhtml/templates/order/address/form.phtml +++ b/app/code/Magento/Sales/view/adminhtml/templates/order/address/form.phtml @@ -3,12 +3,16 @@ * Copyright © Magento, Inc. All rights reserved. * See COPYING.txt for license details. */ + +/** + * @var \Magento\Framework\Escaper $escaper + */ ?>
- escapeHtml( + escapeHtml( __('Changing address information will not recalculate shipping, tax or other order amount.') ) ?>
@@ -18,7 +22,7 @@
- escapeHtml($block->getHeaderText()) ?> + escapeHtml($block->getHeaderText()) ?>
diff --git a/app/code/Magento/Sales/view/adminhtml/templates/order/comments/view.phtml b/app/code/Magento/Sales/view/adminhtml/templates/order/comments/view.phtml index c3a7321a3052f..b7aaadb92580c 100644 --- a/app/code/Magento/Sales/view/adminhtml/templates/order/comments/view.phtml +++ b/app/code/Magento/Sales/view/adminhtml/templates/order/comments/view.phtml @@ -4,14 +4,17 @@ * See COPYING.txt for license details. */ -/** @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer */ +/** + * @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer + * @var \Magento\Framework\Escaper $escaper + */ ?> getEntity()): ?>
+ for="history_comment">escapeHtml(__('Comment Text')) ?>
+ class="admin__control-textarea">escapeHtml($block->getCommentNote()) ?>
- +
getCouponCode()): ?> @@ -19,9 +20,9 @@ getCouponCode()): ?>

- escapeHtml($block->getCouponCode()) ?> - escapeHtml(__('Remove')) ?> + escapeHtml($block->getCouponCode()) ?> + escapeHtml(__('Remove')) ?>

renderEventListenerAsTag( 'onclick', diff --git a/app/code/Magento/Sales/view/adminhtml/templates/order/create/data.phtml b/app/code/Magento/Sales/view/adminhtml/templates/order/create/data.phtml index ced1ea5e7b73a..8feba2c541ec8 100644 --- a/app/code/Magento/Sales/view/adminhtml/templates/order/create/data.phtml +++ b/app/code/Magento/Sales/view/adminhtml/templates/order/create/data.phtml @@ -4,13 +4,16 @@ * See COPYING.txt for license details. */ -/** @var \Magento\Sales\Block\Adminhtml\Order\Create\Data $block */ +/** + * @var \Magento\Sales\Block\Adminhtml\Order\Create\Data $block + * @var \Magento\Framework\Escaper $escaper + */ /** @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer */ ?>
escapeJs($block->getCurrencySymbol($block->getCurrentCurrencyCode()))}') + order.setCurrencySymbol('{$escaper->escapeJs($block->getCurrencySymbol($block->getCurrentCurrencyCode()))}') }); script; ?> @@ -51,7 +54,7 @@ script;
- escapeHtml(__('Address Information')) ?> + escapeHtml(__('Address Information')) ?>
@@ -65,7 +68,7 @@ script;
- escapeHtml(__('Payment & Shipping Information')) ?> + escapeHtml(__('Payment & Shipping Information')) ?>
@@ -87,11 +90,11 @@ script;
- escapeHtml(__('Order Total')) ?> + escapeHtml(__('Order Total')) ?>
- escapeHtml(__('Order History')) ?> + escapeHtml(__('Order History')) ?>
getChildHtml('comment') ?>
@@ -106,16 +109,16 @@ script;
diff --git a/app/code/Magento/Sales/view/adminhtml/templates/order/create/form.phtml b/app/code/Magento/Sales/view/adminhtml/templates/order/create/form.phtml index bd2e08d30ccdd..37a4f2ce4d61d 100644 --- a/app/code/Magento/Sales/view/adminhtml/templates/order/create/form.phtml +++ b/app/code/Magento/Sales/view/adminhtml/templates/order/create/form.phtml @@ -4,12 +4,15 @@ * See COPYING.txt for license details. */ -/** @var \Magento\Sales\Block\Adminhtml\Order\Create\Form $block */ +/** + * @var \Magento\Sales\Block\Adminhtml\Order\Create\Form $block + * @var \Magento\Framework\Escaper $escaper + */ /** @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer */ ?> -
+ getBlockHtml('formkey') ?>
getChildHtml('message') ?> diff --git a/app/code/Magento/Sales/view/adminhtml/templates/order/create/form/account.phtml b/app/code/Magento/Sales/view/adminhtml/templates/order/create/form/account.phtml index 39303568f8899..ac5feb9e4b092 100644 --- a/app/code/Magento/Sales/view/adminhtml/templates/order/create/form/account.phtml +++ b/app/code/Magento/Sales/view/adminhtml/templates/order/create/form/account.phtml @@ -6,12 +6,13 @@ /** * @var $block \Magento\Sales\Block\Adminhtml\Order\Create\Form\Account + * @var \Magento\Framework\Escaper $escaper * @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer */ ?> -
- escapeHtml($block->getHeaderText()) ?> +
+ escapeHtml($block->getHeaderText()) ?>
diff --git a/app/code/Magento/Sales/view/adminhtml/templates/order/create/form/address.phtml b/app/code/Magento/Sales/view/adminhtml/templates/order/create/form/address.phtml index 638ac7e66f769..8a3aefa217f0a 100644 --- a/app/code/Magento/Sales/view/adminhtml/templates/order/create/form/address.phtml +++ b/app/code/Magento/Sales/view/adminhtml/templates/order/create/form/address.phtml @@ -6,6 +6,7 @@ /** * @var \Magento\Sales\Block\Adminhtml\Order\Create\Form\Address $block + * @var \Magento\Framework\Escaper $escaper * @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer */ @@ -40,7 +41,7 @@ if ($block->getIsShipping()): $addressCollectionJson = /* @noEscape */ $block->getAddressCollectionJson(); $scriptString= <<
escapeHtml(__('Ordered')); ?>escapeHtml(__('Ordered')); ?> getQtyOrdered() ?>
escapeHtml(__('Invoiced')); ?>escapeHtml(__('Invoiced')); ?> getQtyInvoiced() ?>
escapeHtml(__('Shipped')); ?>escapeHtml(__('Shipped')); ?> getQtyShipped() ?>
escapeHtml(__('Refunded')); ?>escapeHtml(__('Refunded')); ?> getQtyRefunded() ?>
escapeHtml(__('Canceled')); ?>escapeHtml(__('Canceled')); ?> getQtyCanceled() ?>