Skip to content

Fix accepted types for escaper methods #40114

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 4 commits into
base: 2.4-develop
Choose a base branch
from

Conversation

hostep
Copy link
Contributor

@hostep hostep commented Aug 4, 2025

Description (*)

When performing static analysis using phpstan on level 5 or higher on (custom) phtml files, we often run into false positives that have to do with the kind of data we send to one of the many escape methods.
Also the return type of escapeHtml was not clear as it can return a string or array depending on the type you send to the method.

We fix that in this PR.

Many thanks to @navarr who came up this suggested solution in scope of bitExpert/phpstan-magento#346

Related Pull Requests

Fixed Issues (if relevant)

  1. Fixes Unclear/invalid return types in Magento\Framework\Escaper #40012

Manual testing scenarios (*)

See #40012 & bitExpert/phpstan-magento#346
Maybe I'll find more time later to work out a good example, but I don't have the time at the moment.

Questions or comments

Contribution checklist (*)

  • Pull request has a meaningful description of its purpose
  • All commits are accompanied by meaningful commit messages
  • All new or changed code is covered with unit/integration tests (if applicable)
  • README.md files for modified modules are updated and included in the pull request if any README.md predefined sections require an update
  • All automated tests passed successfully (all builds are green)

Copy link

m2-assistant bot commented Aug 4, 2025

Hi @hostep. Thank you for your contribution!
Here are some useful tips on how you can test your changes using Magento test environment.
❗ Automated tests can be triggered manually with an appropriate comment:

  • @magento run all tests - run or re-run all required tests against the PR changes
  • @magento run <test-build(s)> - run or re-run specific test build(s)
    For example: @magento run Unit Tests

<test-build(s)> is a comma-separated list of build names.

Allowed build names are:
  1. Database Compare
  2. Functional Tests CE
  3. Functional Tests EE
  4. Functional Tests B2B
  5. Integration Tests
  6. Magento Health Index
  7. Sample Data Tests CE
  8. Sample Data Tests EE
  9. Sample Data Tests B2B
  10. Static Tests
  11. Unit Tests
  12. WebAPI Tests
  13. Semantic Version Checker

You can find more information about the builds here
ℹ️ Run only required test builds during development. Run all test builds before sending your pull request for review.


For more details, review the Code Contributions documentation.
Join Magento Community Engineering Slack and ask your questions in #github channel.

@hostep
Copy link
Contributor Author

hostep commented Aug 4, 2025

@magento run all tests

@ct-prd-projects-boards-automation ct-prd-projects-boards-automation bot added the Priority: P2 A defect with this priority could have functionality issues which are not to expectations. label Aug 5, 2025
@github-project-automation github-project-automation bot moved this to Pending Review in Pull Requests Dashboard Aug 5, 2025
@engcom-Hotel engcom-Hotel self-requested a review August 8, 2025 06:51
@engcom-Hotel
Copy link
Contributor

@magento run all tests

Copy link
Contributor

@engcom-Hotel engcom-Hotel left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hello @hostep,

Thanks for the contribution!

Please refer to the below review comment. The failed functional test seems flaky to me, hence re-running the test.

For SVC failure we have created a JIRA for approval. Please fix the review comment, so that we can proceed for the SVC approval.

Thanks

@@ -1,7 +1,7 @@
<?php
/**
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
* Copyright 2013 Adobe
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* Copyright 2013 Adobe
* Copyright 2011 Adobe

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@engcom-Hotel: it should be 2013, not 2011. Looking at the git history, github is guessing it got renamed from app/code/core/Mage/Adminhtml/Model/System/Config/Backend/Price/Scope.php to app/code/core/Mage/Adminhtml/Block/Tax/Rate/ImportExportHeader.php in 2011 and then to app/code/Magento/Adminhtml/Block/Sales/Order/View/History.php in 2013

But going from a PriceScopeBackendConfig to a TaxRateImportExportHeader to a SalesOrderViewHistoryBlock makes no sense to me. So in my opinion it should be 2013.

Can you double check this again?

I didn't check the other files, only this one...

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If you really believe it should be 2011, go ahead and change it yourself because I'm unavailable for the next 2 weeks, since I'll go on holiday. Thanks!

@@ -1,7 +1,7 @@
<?php
/**
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
* Copyright 2013 Adobe
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* Copyright 2013 Adobe
* Copyright 2011 Adobe

@@ -1,7 +1,7 @@
<?php
/**
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
* Copyright 2014 Adobe
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* Copyright 2014 Adobe
* Copyright 2013 Adobe

@@ -1,7 +1,7 @@
<?php
/**
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
* Copyright 2014 Adobe
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* Copyright 2014 Adobe
* Copyright 2011 Adobe

@engcom-Hotel
Copy link
Contributor

@magento run Functional Tests EE, Functional Tests B2B

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Priority: P2 A defect with this priority could have functionality issues which are not to expectations. Progress: review
Projects
Status: Review in Progress
Development

Successfully merging this pull request may close these issues.

Unclear/invalid return types in Magento\Framework\Escaper
2 participants