From 83c1411bc6d868d744bb6df838a3b82fe6a0613f Mon Sep 17 00:00:00 2001 From: Vladimir Malik Date: Fri, 2 Oct 2020 09:23:25 +0300 Subject: [PATCH] XSS prevention: escaping in phtml. Use $block instead $this. --- .../templates/config/form/validate.phtml | 10 +++---- .../templates/config/support/tab.phtml | 29 ++++++++++--------- 2 files changed, 21 insertions(+), 18 deletions(-) diff --git a/view/adminhtml/templates/config/form/validate.phtml b/view/adminhtml/templates/config/form/validate.phtml index 7a78672..4e2ff03 100644 --- a/view/adminhtml/templates/config/form/validate.phtml +++ b/view/adminhtml/templates/config/form/validate.phtml @@ -31,10 +31,10 @@ */ ?> - +
- - - - + escapeHtml(__('Validating API credentials')); ?> + + +
diff --git a/view/adminhtml/templates/config/support/tab.phtml b/view/adminhtml/templates/config/support/tab.phtml index c5adaa0..9de6281 100644 --- a/view/adminhtml/templates/config/support/tab.phtml +++ b/view/adminhtml/templates/config/support/tab.phtml @@ -1,5 +1,5 @@
@@ -13,32 +13,32 @@ escapeHtml(__('Supported Magento versions'));?>: - escapeHtml($this->getSupportedMagentoVersions()); ?> + escapeHtml($block->getSupportedMagentoVersions()); ?>
  • escapeHtml(__('Extension version'));?>: - escapeHtml($this->getVersionNumber()); ?> + escapeHtml($block->getVersionNumber()); ?>
  • escapeHtml(__('Your PHP version'));?>: - - escapeHtml(implode('.', $this->getPhpVersionArray())); ?> + escapeHtml(implode('.', $block->getPhpVersionArray())); ?>   - phpVersionCheck()) { + phpVersionCheck()) { case 1: - echo ''; break; case 0: - echo ''; break; default: - echo ''; break; @@ -53,15 +53,18 @@
    -

    escapeHtml(__('Support'));?>

    +

    escapeHtml(__('Support')); ?>