diff --git a/app/code/Magento/CatalogWidget/view/adminhtml/templates/product/widget/conditions.phtml b/app/code/Magento/CatalogWidget/view/adminhtml/templates/product/widget/conditions.phtml index 4b1750eba9f19..56b97ef9fd736 100644 --- a/app/code/Magento/CatalogWidget/view/adminhtml/templates/product/widget/conditions.phtml +++ b/app/code/Magento/CatalogWidget/view/adminhtml/templates/product/widget/conditions.phtml @@ -4,16 +4,19 @@ * See COPYING.txt for license details. */ -/** @var \Magento\CatalogWidget\Block\Product\Widget\Conditions $block */ +/** + * @var \Magento\CatalogWidget\Block\Product\Widget\Conditions $block + * @var \Magento\Framework\Escaper $escaper + */ /** @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer */ $element = $block->getElement(); -$fieldId = $element->getHtmlContainerId() ? ' id="' . $block->escapeHtmlAttr($element->getHtmlContainerId()) . '"' : ''; -$fieldClass = 'field admin__field field-' . $block->escapeHtmlAttr($element->getId()) . ' ' - . $block->escapeHtmlAttr($element->getCssClass()); +$fieldId = $element->getHtmlContainerId() ? ' id="' . $escaper->escapeHtmlAttr($element->getHtmlContainerId()) . '"' : ''; +$fieldClass = 'field admin__field field-' . $escaper->escapeHtmlAttr($element->getId()) . ' ' + . $escaper->escapeHtmlAttr($element->getCssClass()); $fieldClass .= $element->getRequired() ? ' required' : ''; $fieldAttributes = $fieldId . ' class="' . $fieldClass . '" ' - . $block->getUiId('form-field', $block->escapeHtmlAttr($element->getId())); + . $block->getUiId('form-field', $escaper->escapeHtmlAttr($element->getId())); ?> > getLabelHtml() ?> @@ -31,8 +34,8 @@ $fieldAttributes = $fieldId . ' class="' . $fieldClass . '" ' "Magento_Rule/rules", "prototype" ], function(VarienRulesForm){ - window.{$block->escapeJs($block->getHtmlId())} = new VarienRulesForm('{$block->escapeJs($block->getHtmlId())}', - '{$block->escapeUrl($block->getNewChildUrl())}'); + window.{$escaper->escapeJs($block->getHtmlId())} = new VarienRulesForm('{$escaper->escapeJs($block->getHtmlId())}', + '{$escaper->escapeUrl($block->getNewChildUrl())}'); }); script; ?> diff --git a/app/code/Magento/CatalogWidget/view/frontend/templates/product/widget/content/grid.phtml b/app/code/Magento/CatalogWidget/view/frontend/templates/product/widget/content/grid.phtml index 881d8b28dfaeb..74a3f26804799 100644 --- a/app/code/Magento/CatalogWidget/view/frontend/templates/product/widget/content/grid.phtml +++ b/app/code/Magento/CatalogWidget/view/frontend/templates/product/widget/content/grid.phtml @@ -5,7 +5,10 @@ */ use Magento\Framework\App\Action\Action; -/** @var \Magento\CatalogWidget\Block\Product\ProductsList $block */ +/** + * @var \Magento\CatalogWidget\Block\Product\ProductsList $block + * @var \Magento\Framework\Escaper $escaper + */ ?> getProductCollection() && $block->getProductCollection()->getSize())) : ?> "> getTitle()) : ?>
- escapeHtml(__($block->getTitle())) ?> + escapeHtml(__($block->getTitle())) ?>
@@ -36,15 +39,15 @@ use Magento\Framework\App\Action\Action; ' : '
  • ' ?>
    - + getImage($_item, $image)->toHtml() ?>
    - - escapeHtml($_item->getName()) ?> + escapeHtml($_item->getName()) ?> @@ -62,21 +65,21 @@ use Magento\Framework\App\Action\Action;
    isSaleable()) : ?> getAddToCartPostParams($_item); ?> -
    - + + getBlockHtml('formkey') ?>
    getIsSalable()) : ?> -
    escapeHtml(__('In stock')) ?>
    +
    escapeHtml(__('In stock')) ?>
    -
    escapeHtml(__('Out of stock')) ?>
    +
    escapeHtml(__('Out of stock')) ?>
    @@ -85,14 +88,14 @@ use Magento\Framework\App\Action\Action;