Skip to content

Chore: Offline Payments - Replace Block Escaping with Escaper #37062

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -3,19 +3,23 @@
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
*/
declare(strict_types=1);

/**
* @var $block \Magento\OfflinePayments\Block\Form\Banktransfer
* @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer
*/
use Magento\Framework\Escaper;
use Magento\Framework\View\Helper\SecureHtmlRenderer;
use Magento\OfflinePayments\Block\Form\Banktransfer;

/** @var Escaper $escaper */
/** @var SecureHtmlRenderer $secureRenderer */
/** @var Banktransfer $block */
$instructions = $block->getInstructions();
?>
<?php if ($instructions): ?>
<?php $methodCode = $block->escapeHtml($block->getMethodCode());?>
<?php $methodCode = $escaper->escapeHtml($block->getMethodCode());?>
<ul class="form-list checkout-agreements" id="payment_form_<?= /* @noEscape */ $methodCode ?>">
<li>
<div class="<?= /* @noEscape */ $methodCode ?>-instructions-content checkout-agreement-item-content">
<?= /* @noEscape */ nl2br($block->escapeHtml($instructions)) ?>
<?= /* @noEscape */ nl2br($escaper->escapeHtml($instructions)) ?>
</div>
</li>
</ul>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,19 +3,23 @@
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
*/
declare(strict_types=1);

/**
* @var $block \Magento\OfflinePayments\Block\Form\Cashondelivery
* @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer
*/
use Magento\Framework\Escaper;
use Magento\Framework\View\Helper\SecureHtmlRenderer;
use Magento\OfflinePayments\Block\Form\Cashondelivery;

/** @var Escaper $escaper */
/** @var SecureHtmlRenderer $secureRenderer */
/** @var Cashondelivery $block */
$instructions = $block->getInstructions();
?>
<?php if ($instructions): ?>
<?php $methodCode = $block->escapeHtml($block->getMethodCode());?>
<?php $methodCode = $escaper->escapeHtml($block->getMethodCode());?>
<ul class="form-list checkout-agreements" id="payment_form_<?= /* @noEscape */ $methodCode ?>">
<li>
<div class="<?= /* @noEscape */ $methodCode ?>-instructions-content checkout-agreement-item-content">
<?= /* @noEscape */ nl2br($block->escapeHtml($instructions)) ?>
<?= /* @noEscape */ nl2br($escaper->escapeHtml($instructions)) ?>
</div>
</li>
</ul>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,27 +3,31 @@
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
*/
declare(strict_types=1);

/**
* @var $block \Magento\OfflinePayments\Block\Form\Checkmo
* @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer
*/
use Magento\Framework\Escaper;
use Magento\Framework\View\Helper\SecureHtmlRenderer;
use Magento\OfflinePayments\Block\Form\Checkmo;

/** @var Escaper $escaper */
/** @var Checkmo $block */
/** @var SecureHtmlRenderer $secureRenderer */
?>
<fieldset class="admin__fieldset payment-method" id="payment_form_<?= $block->escapeHtml($block->getMethodCode()) ?>" >
<fieldset class="admin__fieldset payment-method" id="payment_form_<?= $escaper->escapeHtml($block->getMethodCode()) ?>" >
<?php if ($block->getMethod()->getPayableTo()): ?>
<label class="label"><span><?= $block->escapeHtml(__('Make Check payable to:')) ?></span></label>
<?= $block->escapeHtml($block->getMethod()->getPayableTo()) ?>
<label class="label"><span><?= $escaper->escapeHtml(__('Make Check payable to:')) ?></span></label>
<?= $escaper->escapeHtml($block->getMethod()->getPayableTo()) ?>
<?php endif; ?>
<?php if ($block->getMethod()->getMailingAddress()): ?>
<div class="admin__field">
<label class="admin__field-label"><span><?= $block->escapeHtml(__('Send Check to:')) ?></span></label>
<label class="admin__field-label"><span><?= $escaper->escapeHtml(__('Send Check to:')) ?></span></label>
<div class="admin__field-control checkmo-mailing-address">
<?= /* @noEscape */ nl2br($block->escapeHtml($block->getMethod()->getMailingAddress())) ?>
<?= /* @noEscape */ nl2br($escaper->escapeHtml($block->getMethod()->getMailingAddress())) ?>
</div>
</div>
<?php endif; ?>
</fieldset>
<?= /* @noEscape */ $secureRenderer->renderStyleAsTag(
"display:none",
'fieldset#payment_form_' . $block->escapeJs($block->getMethodCode())
'fieldset#payment_form_' . $escaper->escapeJs($block->getMethodCode())
) ?>
Original file line number Diff line number Diff line change
Expand Up @@ -3,26 +3,30 @@
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
*/
declare(strict_types=1);

/**
* @var $block \Magento\OfflinePayments\Block\Form\Purchaseorder
* @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer
*/
use Magento\Framework\Escaper;
use Magento\Framework\View\Helper\SecureHtmlRenderer;
use Magento\OfflinePayments\Block\Form\Purchaseorder;

/** @var Escaper $escaper */
/** @var Purchaseorder $block */
/** @var SecureHtmlRenderer $secureRenderer */
?>
<fieldset class="admin__fieldset payment-method" id="payment_form_<?= $block->escapeHtml($block->getMethodCode()) ?>">
<fieldset class="admin__fieldset payment-method" id="payment_form_<?= $escaper->escapeHtml($block->getMethodCode()) ?>">
<div class="admin__field _required">
<label for="po_number" class="admin__field-label">
<span><?= $block->escapeHtml(__('Purchase Order Number')) ?></span>
<span><?= $escaper->escapeHtml(__('Purchase Order Number')) ?></span>
</label>
<div class="admin__field-control">
<input type="text" id="po_number" name="payment[po_number]"
title="<?= $block->escapeHtml(__("Purchase Order Number")) ?>"
title="<?= $escaper->escapeHtml(__("Purchase Order Number")) ?>"
class="required-entry admin__control-text"
value="<?= /* @noEscape */ $block->getInfoData('po_number') ?>"/>
</div>
</div>
</fieldset>
<?= /* @noEscape */ $secureRenderer->renderStyleAsTag(
"display:none",
'fieldset#payment_form_' . $block->escapeJs($block->getMethodCode())
'fieldset#payment_form_' . $escaper->escapeJs($block->getMethodCode())
) ?>
Original file line number Diff line number Diff line change
Expand Up @@ -3,21 +3,24 @@
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
*/
declare(strict_types=1);

/**
* @var $block \Magento\OfflinePayments\Block\Info\Checkmo
*/
use Magento\Framework\Escaper;
use Magento\OfflinePayments\Block\Info\Checkmo;

/** @var Escaper $escaper */
/** @var Checkmo $block */
$paymentTitle = $block->getMethod()->getConfigData('title', $block->getInfo()->getOrder()->getStoreId());
?>
<?= $block->escapeHtml($paymentTitle) ?>
<?= $escaper->escapeHtml($paymentTitle) ?>
<?php if ($block->getInfo()->getAdditionalInformation()) : ?>
<?php if ($block->getPayableTo()) : ?>
<br /><?= $block->escapeHtml(__('Make Check payable to: %1', $block->getPayableTo())) ?>
<br /><?= $escaper->escapeHtml(__('Make Check payable to: %1', $block->getPayableTo())) ?>
<?php endif; ?>
<?php if ($block->getMailingAddress()) : ?>
<label><?= $block->escapeHtml(__('Send Check to:')) ?></label>
<label><?= $escaper->escapeHtml(__('Send Check to:')) ?></label>
<div class="checkmo-mailing-address">
<?= /* @noEscape */ nl2br($block->escapeHtml($block->getMailingAddress())) ?>
<?= /* @noEscape */ nl2br($escaper->escapeHtml($block->getMailingAddress())) ?>
</div>
<?php endif; ?>
<?php endif; ?>
Original file line number Diff line number Diff line change
Expand Up @@ -3,24 +3,27 @@
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
*/
declare(strict_types=1);

/**
* @var $block \Magento\OfflinePayments\Block\Info\Checkmo
*/
use Magento\Framework\Escaper;
use Magento\OfflinePayments\Block\Info\Checkmo;

/** @var Escaper $escaper */
/** @var Checkmo $block */
$paymentTitle = $block->getMethod()->getConfigData('title', $block->getInfo()->getOrder()->getStoreId());
?>
<?= $block->escapeHtml($paymentTitle) ?>
<?= $escaper->escapeHtml($paymentTitle) ?>
{{pdf_row_separator}}
<?php if ($block->getInfo()->getAdditionalInformation()) : ?>
{{pdf_row_separator}}
<?php if ($block->getPayableTo()) : ?>
<?= $block->escapeHtml(__('Make Check payable to: %1', $block->getPayableTo())) ?>
<?= $escaper->escapeHtml(__('Make Check payable to: %1', $block->getPayableTo())) ?>
{{pdf_row_separator}}
<?php endif; ?>
<?php if ($block->getMailingAddress()) : ?>
<?= $block->escapeHtml(__('Send Check to:')) ?>
<?= $escaper->escapeHtml(__('Send Check to:')) ?>
{{pdf_row_separator}}
<?= /* @noEscape */ nl2br($block->escapeHtml($block->getMailingAddress())) ?>
<?= /* @noEscape */ nl2br($escaper->escapeHtml($block->getMailingAddress())) ?>
{{pdf_row_separator}}
<?php endif; ?>
<?php endif; ?>
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,13 @@
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
*/
/**
* @var $block \Magento\OfflinePayments\Block\Info\Purchaseorder
*/
declare(strict_types=1);

use Magento\Framework\Escaper;
use Magento\OfflinePayments\Block\Info\Purchaseorder;

/** @var Escaper $escaper */
/** @var Purchaseorder $block */
?>
<?= $block->escapeHtml(__('Purchase Order Number: %1', $block->getInfo()->getPoNumber())) ?>
<?= $escaper->escapeHtml(__('Purchase Order Number: %1', $block->getInfo()->getPoNumber())) ?>
{{pdf_row_separator}}
Original file line number Diff line number Diff line change
Expand Up @@ -3,15 +3,19 @@
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
*/
/**
* @var $block \Magento\OfflinePayments\Block\Info\Purchaseorder
*/
declare(strict_types=1);

use Magento\Framework\Escaper;
use Magento\OfflinePayments\Block\Info\Purchaseorder;

/** @var Escaper $escaper */
/** @var Purchaseorder $block */
$paymentTitle = $block->getMethod()->getConfigData('title', $block->getInfo()->getOrder()->getStoreId());
?>
<div class="order-payment-method-name"><?= $block->escapeHtml($paymentTitle) ?></div>
<div class="order-payment-method-name"><?= $escaper->escapeHtml($paymentTitle) ?></div>
<table class="data-table admin__table-secondary">
<tr>
<th><?= $block->escapeHtml(__('Purchase Order Number')) ?>:</th>
<td><?= $block->escapeHtml($block->getInfo()->getPoNumber()) ?></td>
<th><?= $escaper->escapeHtml(__('Purchase Order Number')) ?>:</th>
<td><?= $escaper->escapeHtml($block->getInfo()->getPoNumber()) ?></td>
</tr>
</table>
Original file line number Diff line number Diff line change
Expand Up @@ -3,23 +3,26 @@
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
*/
declare(strict_types=1);

/**
* @var $block \Magento\OfflinePayments\Block\Info\Checkmo
*/
use Magento\Framework\Escaper;
use Magento\OfflinePayments\Block\Info\Checkmo;

/** @var Escaper $escaper */
/** @var Checkmo $block */
?>
<?= $block->escapeHtml($block->getMethod()->getTitle()) ?>
<?= $escaper->escapeHtml($block->getMethod()->getTitle()) ?>
{{pdf_row_separator}}
<?php if ($block->getInfo()->getAdditionalInformation()) : ?>
{{pdf_row_separator}}
<?php if ($block->getPayableTo()) : ?>
<?= $block->escapeHtml(__('Make Check payable to: %1', $block->getPayableTo())) ?>
<?= $escaper->escapeHtml(__('Make Check payable to: %1', $block->getPayableTo())) ?>
{{pdf_row_separator}}
<?php endif; ?>
<?php if ($block->getMailingAddress()) : ?>
<?= $block->escapeHtml(__('Send Check to:')) ?>
<?= $escaper->escapeHtml(__('Send Check to:')) ?>
{{pdf_row_separator}}
<?= /* @noEscape */ nl2br($block->escapeHtml($block->getMailingAddress())) ?>
<?= /* @noEscape */ nl2br($escaper->escapeHtml($block->getMailingAddress())) ?>
{{pdf_row_separator}}
<?php endif; ?>
<?php endif; ?>
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,13 @@
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
*/
/**
* @var $block \Magento\OfflinePayments\Block\Info\Purchaseorder
*/
declare(strict_types=1);

use Magento\Framework\Escaper;
use Magento\OfflinePayments\Block\Info\Purchaseorder;

/** @var Escaper $escaper */
/** @var Purchaseorder $block */
?>
<?= $block->escapeHtml(__('Purchase Order Number: %1', $block->getInfo()->getPoNumber())) ?>
<?= $escaper->escapeHtml(__('Purchase Order Number: %1', $block->getInfo()->getPoNumber())) ?>
{{pdf_row_separator}}
Original file line number Diff line number Diff line change
Expand Up @@ -3,18 +3,22 @@
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
*/
declare(strict_types=1);

/**
* @var $block \Magento\OfflinePayments\Block\Form\Banktransfer
* @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer
*/
use Magento\Framework\Escaper;
use Magento\Framework\View\Helper\SecureHtmlRenderer;
use Magento\OfflinePayments\Block\Form\Banktransfer;

/** @var Escaper $escaper */
/** @var SecureHtmlRenderer $secureRenderer */
/** @var Banktransfer $block */
$instructions = $block->getInstructions();
?>
<?php if ($instructions): ?>
<?php $methodCode = $block->escapeHtml($block->getMethodCode());?>
<?php $methodCode = $escaper->escapeHtml($block->getMethodCode());?>
<div class="items <?= /* @noEscape */ $methodCode ?> instructions agreement checkout-agreement-item-content"
id="payment_form_<?= /* @noEscape */ $methodCode ?>">
<?= /* @noEscape */ nl2br($block->escapeHtml($instructions)) ?>
<?= /* @noEscape */ nl2br($escaper->escapeHtml($instructions)) ?>
</div>
<?= /* @noEscape */ $secureRenderer->renderStyleAsTag(
"display:none",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,18 +3,22 @@
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
*/
declare(strict_types=1);

/**
* @var $block \Magento\OfflinePayments\Block\Form\Cashondelivery
* @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer
*/
use Magento\Framework\Escaper;
use Magento\Framework\View\Helper\SecureHtmlRenderer;
use Magento\OfflinePayments\Block\Form\Cashondelivery;

/** @var Escaper $escaper */
/** @var SecureHtmlRenderer $secureRenderer */
/** @var Cashondelivery $block */
$instructions = $block->getInstructions();
?>
<?php if ($instructions): ?>
<?php $methodCode = $block->escapeHtml($block->getMethodCode());?>
<?php $methodCode = $escaper->escapeHtml($block->getMethodCode());?>
<div class="items <?= /* @noEscape */ $methodCode ?> instructions agreement"
id="payment_form_<?= /* @noEscape */ $methodCode ?>">
<?= /* @noEscape */ nl2br($block->escapeHtml($instructions)) ?>
<?= /* @noEscape */ nl2br($escaper->escapeHtml($instructions)) ?>
</div>
<?= /* @noEscape */ $secureRenderer->renderStyleAsTag(
"display:none",
Expand Down
Loading