From 1e8ba207b626bfdbff611cbc7a047b6cc74b5cf2 Mon Sep 17 00:00:00 2001 From: Viktor Tymchynskyi Date: Fri, 11 Sep 2015 14:08:38 +0300 Subject: [PATCH] MAGETWO-41781: Create static test - Xss potentially unsafe outputs in *.phtml templates are marked by /* @escapeNotVerified */ annotation --- .../templates/notification/window.phtml | 12 +- .../adminhtml/templates/system/messages.phtml | 8 +- .../templates/system/messages/popup.phtml | 4 +- .../adminhtml/templates/toolbar_entry.phtml | 30 ++-- .../templates/directpost/iframe.phtml | 4 +- .../adminhtml/templates/directpost/info.phtml | 58 +++---- .../order/view/info/fraud_details.phtml | 14 +- .../templates/admin/access_denied.phtml | 8 +- .../adminhtml/templates/admin/formkey.phtml | 2 +- .../adminhtml/templates/admin/login.phtml | 12 +- .../templates/admin/login_buttons.phtml | 2 +- .../templates/admin/overlay_popup.phtml | 2 +- .../view/adminhtml/templates/admin/page.phtml | 4 +- .../adminhtml/templates/dashboard/graph.phtml | 10 +- .../templates/dashboard/graph/disabled.phtml | 4 +- .../adminhtml/templates/dashboard/grid.phtml | 24 +-- .../adminhtml/templates/dashboard/index.phtml | 10 +- .../templates/dashboard/salebar.phtml | 6 +- .../templates/dashboard/searches.phtml | 4 +- .../templates/dashboard/store/switcher.phtml | 14 +- .../templates/dashboard/totalbar.phtml | 6 +- .../totalbar/refreshstatistics.phtml | 6 +- .../adminhtml/templates/media/uploader.phtml | 14 +- .../view/adminhtml/templates/menu.phtml | 2 +- .../adminhtml/templates/page/copyright.phtml | 4 +- .../adminhtml/templates/page/footer.phtml | 4 +- .../adminhtml/templates/page/header.phtml | 22 +-- .../templates/page/js/calendar.phtml | 36 ++--- .../templates/page/js/require_js.phtml | 4 +- .../adminhtml/templates/page/locale.phtml | 6 +- .../adminhtml/templates/page/notices.phtml | 6 +- .../adminhtml/templates/page/report.phtml | 2 +- .../adminhtml/templates/pageactions.phtml | 2 +- .../adminhtml/templates/store/switcher.phtml | 28 ++-- .../switcher/form/renderer/fieldset.phtml | 8 +- .../form/renderer/fieldset/element.phtml | 10 +- .../templates/system/autocomplete.phtml | 6 +- .../templates/system/cache/additional.phtml | 22 +-- .../templates/system/cache/edit.phtml | 16 +- .../templates/system/design/edit.phtml | 2 +- .../adminhtml/templates/system/search.phtml | 4 +- .../templates/widget/accordion.phtml | 2 +- .../templates/widget/breadcrumbs.phtml | 2 +- .../adminhtml/templates/widget/button.phtml | 4 +- .../templates/widget/button/split.phtml | 4 +- .../templates/widget/form/container.phtml | 8 +- .../templates/widget/form/element.phtml | 38 ++--- .../widget/form/element/gallery.phtml | 34 ++-- .../widget/form/renderer/fieldset.phtml | 32 ++-- .../form/renderer/fieldset/element.phtml | 10 +- .../adminhtml/templates/widget/grid.phtml | 64 ++++---- .../templates/widget/grid/column_set.phtml | 52 +++--- .../templates/widget/grid/export.phtml | 8 +- .../templates/widget/grid/extended.phtml | 98 +++++------ .../templates/widget/grid/massaction.phtml | 30 ++-- .../widget/grid/massaction_extended.phtml | 26 +-- .../templates/widget/grid/serializer.phtml | 12 +- .../adminhtml/templates/widget/tabs.phtml | 36 ++--- .../templates/widget/tabshoriz.phtml | 24 +-- .../adminhtml/templates/widget/tabsleft.phtml | 14 +- .../adminhtml/templates/backup/dialogs.phtml | 68 ++++---- .../adminhtml/templates/backup/left.phtml | 2 +- .../view/adminhtml/templates/data_js.phtml | 2 +- .../view/adminhtml/templates/form.phtml | 54 +++---- .../frontend/templates/PayPal/shortcut.phtml | 16 +- .../templates/creditcard/delete.phtml | 26 +-- .../frontend/templates/creditcard/edit.phtml | 96 +++++------ .../frontend/templates/creditcard/index.phtml | 20 +-- .../view/frontend/templates/data_js.phtml | 2 +- .../view/frontend/templates/form.phtml | 60 +++---- .../product/edit/tab/attributes/extend.phtml | 14 +- .../composite/fieldset/options/bundle.phtml | 4 +- .../fieldset/options/type/checkbox.phtml | 26 +-- .../fieldset/options/type/multi.phtml | 18 +-- .../fieldset/options/type/radio.phtml | 36 ++--- .../fieldset/options/type/select.phtml | 28 ++-- .../templates/product/edit/bundle.phtml | 10 +- .../product/edit/bundle/option.phtml | 56 +++---- .../edit/bundle/option/selection.phtml | 52 +++--- .../creditmemo/create/items/renderer.phtml | 56 +++---- .../creditmemo/view/items/renderer.phtml | 22 +-- .../sales/invoice/create/items/renderer.phtml | 54 +++---- .../sales/invoice/view/items/renderer.phtml | 22 +-- .../sales/order/view/items/renderer.phtml | 56 +++---- .../shipment/create/items/renderer.phtml | 20 +-- .../sales/shipment/view/items/renderer.phtml | 20 +-- .../templates/product/price/final_price.phtml | 16 +- .../product/price/selection/amount.phtml | 2 +- .../templates/product/price/tier_prices.phtml | 4 +- .../catalog/product/view/backbutton.phtml | 2 +- .../catalog/product/view/customize.phtml | 2 +- .../catalog/product/view/options/notice.phtml | 2 +- .../catalog/product/view/summary.phtml | 14 +- .../catalog/product/view/type/bundle.phtml | 8 +- .../view/type/bundle/option/checkbox.phtml | 22 +-- .../view/type/bundle/option/multi.phtml | 20 +-- .../view/type/bundle/option/radio.phtml | 38 ++--- .../view/type/bundle/option/select.phtml | 32 ++-- .../product/view/type/bundle/options.phtml | 6 +- .../order/items/creditmemo/default.phtml | 12 +- .../email/order/items/invoice/default.phtml | 12 +- .../email/order/items/order/default.phtml | 20 +-- .../email/order/items/shipment/default.phtml | 12 +- .../order/creditmemo/items/renderer.phtml | 12 +- .../sales/order/invoice/items/renderer.phtml | 10 +- .../sales/order/items/renderer.phtml | 30 ++-- .../sales/order/shipment/items/renderer.phtml | 12 +- .../view/adminhtml/templates/default.phtml | 20 +-- .../view/frontend/templates/default.phtml | 22 +-- .../catalog/category/checkboxes/tree.phtml | 18 +-- .../templates/catalog/category/edit.phtml | 2 +- .../catalog/category/edit/form.phtml | 34 ++-- .../templates/catalog/category/tree.phtml | 32 ++-- .../catalog/category/widget/tree.phtml | 30 ++-- .../form/renderer/fieldset/element.phtml | 16 +- .../catalog/product/attribute/form.phtml | 8 +- .../catalog/product/attribute/js.phtml | 4 +- .../catalog/product/attribute/labels.phtml | 6 +- .../catalog/product/attribute/options.phtml | 22 +-- .../catalog/product/attribute/set/main.phtml | 34 ++-- .../product/attribute/set/toolbar/add.phtml | 2 +- .../catalog/product/composite/configure.phtml | 2 +- .../product/composite/fieldset/options.phtml | 2 +- .../fieldset/options/type/date.phtml | 20 +-- .../fieldset/options/type/file.phtml | 30 ++-- .../fieldset/options/type/select.phtml | 2 +- .../fieldset/options/type/text.phtml | 8 +- .../product/composite/fieldset/qty.phtml | 4 +- .../templates/catalog/product/edit.phtml | 24 +-- .../product/edit/action/attribute.phtml | 4 +- .../product/edit/action/inventory.phtml | 152 +++++++++--------- .../product/edit/action/websites.phtml | 18 +-- .../catalog/product/edit/attribute_set.phtml | 2 +- .../product/edit/category/new/form.phtml | 2 +- .../catalog/product/edit/options.phtml | 4 +- .../catalog/product/edit/options/option.phtml | 42 ++--- .../product/edit/options/type/date.phtml | 6 +- .../product/edit/options/type/file.phtml | 14 +- .../product/edit/options/type/select.phtml | 12 +- .../product/edit/options/type/text.phtml | 8 +- .../catalog/product/edit/price/group.phtml | 46 +++--- .../catalog/product/edit/price/tier.phtml | 50 +++--- .../catalog/product/edit/serializer.phtml | 2 +- .../catalog/product/edit/websites.phtml | 12 +- .../catalog/product/helper/gallery.phtml | 42 ++--- .../templates/catalog/product/js.phtml | 8 +- .../templates/catalog/product/tab/alert.phtml | 2 +- .../catalog/product/tab/inventory.phtml | 134 +++++++-------- .../templates/catalog/wysiwyg/js.phtml | 2 +- .../product/edit/attribute/search.phtml | 10 +- .../templates/product/edit/tabs.phtml | 54 +++---- .../product/grid/massaction_extended.phtml | 26 +-- .../adminhtml/templates/rss/grid/link.phtml | 2 +- .../product/price/amount/default.phtml | 16 +- .../product/price/configured_price.phtml | 2 +- .../templates/product/price/default.phtml | 2 +- .../templates/product/price/final_price.phtml | 12 +- .../templates/product/price/tier_prices.phtml | 10 +- .../templates/category/description.phtml | 2 +- .../frontend/templates/category/image.phtml | 2 +- .../frontend/templates/category/rss.phtml | 2 +- .../category/widget/link/link_block.phtml | 4 +- .../category/widget/link/link_inline.phtml | 4 +- .../frontend/templates/navigation/left.phtml | 10 +- .../templates/product/compare/link.phtml | 6 +- .../templates/product/compare/list.phtml | 42 ++--- .../templates/product/compare/sidebar.phtml | 14 +- .../frontend/templates/product/gallery.phtml | 18 +-- .../frontend/templates/product/image.phtml | 10 +- .../product/image_with_borders.phtml | 14 +- .../frontend/templates/product/list.phtml | 40 ++--- .../templates/product/list/items.phtml | 58 +++---- .../templates/product/list/toolbar.phtml | 2 +- .../product/list/toolbar/amount.phtml | 6 +- .../product/list/toolbar/limiter.phtml | 8 +- .../product/list/toolbar/sorter.phtml | 12 +- .../product/list/toolbar/viewmode.phtml | 22 +-- .../frontend/templates/product/listing.phtml | 12 +- .../templates/product/view/additional.phtml | 2 +- .../templates/product/view/addto.phtml | 14 +- .../templates/product/view/addtocart.phtml | 10 +- .../templates/product/view/attribute.phtml | 6 +- .../templates/product/view/attributes.phtml | 4 +- .../templates/product/view/description.phtml | 2 +- .../templates/product/view/details.phtml | 14 +- .../templates/product/view/form.phtml | 6 +- .../templates/product/view/gallery.phtml | 34 ++-- .../templates/product/view/mailto.phtml | 6 +- .../product/view/opengraph/currency.phtml | 4 +- .../product/view/opengraph/general.phtml | 10 +- .../templates/product/view/options.phtml | 2 +- .../product/view/options/type/date.phtml | 18 +-- .../product/view/options/type/file.phtml | 40 ++--- .../product/view/options/type/select.phtml | 6 +- .../product/view/options/type/text.phtml | 18 +-- .../product/view/options/wrapper.phtml | 2 +- .../templates/product/view/type/default.phtml | 8 +- .../product/widget/link/link_block.phtml | 4 +- .../product/widget/link/link_inline.phtml | 4 +- .../widget/new/column/new_default_list.phtml | 38 ++--- .../widget/new/column/new_images_list.phtml | 8 +- .../widget/new/column/new_names_list.phtml | 10 +- .../product/widget/new/content/new_grid.phtml | 44 ++--- .../product/widget/new/content/new_list.phtml | 50 +++--- .../frontend/templates/qtyincrements.phtml | 2 +- .../templates/stockqty/composite.phtml | 20 +-- .../frontend/templates/stockqty/default.phtml | 4 +- .../adminhtml/templates/promo/fieldset.phtml | 6 +- .../frontend/templates/advanced/form.phtml | 62 +++---- .../frontend/templates/advanced/link.phtml | 4 +- .../frontend/templates/advanced/result.phtml | 10 +- .../view/frontend/templates/result.phtml | 6 +- .../templates/product/widget/conditions.phtml | 4 +- .../product/widget/content/grid.phtml | 44 ++--- .../view/frontend/templates/button.phtml | 2 +- .../view/frontend/templates/cart/coupon.phtml | 12 +- .../view/frontend/templates/cart/form.phtml | 18 +-- .../cart/item/configure/updatecart.phtml | 8 +- .../templates/cart/item/default.phtml | 32 ++-- .../templates/cart/item/price/sidebar.phtml | 4 +- .../cart/item/renderer/actions/edit.phtml | 4 +- .../cart/item/renderer/actions/remove.phtml | 4 +- .../frontend/templates/cart/methods.phtml | 2 +- .../frontend/templates/cart/minicart.phtml | 10 +- .../frontend/templates/cart/noItems.phtml | 4 +- .../frontend/templates/cart/shipping.phtml | 10 +- .../view/frontend/templates/cart/totals.phtml | 2 +- .../frontend/templates/item/price/row.phtml | 2 +- .../frontend/templates/item/price/unit.phtml | 2 +- .../view/frontend/templates/onepage.phtml | 10 +- .../frontend/templates/onepage/billing.phtml | 82 +++++----- .../frontend/templates/onepage/failure.phtml | 6 +- .../frontend/templates/onepage/link.phtml | 6 +- .../frontend/templates/onepage/payment.phtml | 6 +- .../templates/onepage/payment/methods.phtml | 14 +- .../templates/onepage/review/button.phtml | 6 +- .../templates/onepage/review/info.phtml | 16 +- .../templates/onepage/review/item.phtml | 6 +- .../review/item/price/row_excl_tax.phtml | 2 +- .../review/item/price/row_incl_tax.phtml | 2 +- .../review/item/price/unit_excl_tax.phtml | 2 +- .../review/item/price/unit_incl_tax.phtml | 2 +- .../templates/onepage/review/totals.phtml | 10 +- .../frontend/templates/onepage/shipping.phtml | 68 ++++---- .../templates/onepage/shipping_method.phtml | 4 +- .../onepage/shipping_method/additional.phtml | 2 +- .../onepage/shipping_method/available.phtml | 14 +- .../frontend/templates/registration.phtml | 6 +- .../frontend/templates/shipping/price.phtml | 2 +- .../view/frontend/templates/success.phtml | 4 +- .../frontend/templates/total/default.phtml | 6 +- .../templates/additional_agreements.phtml | 12 +- .../view/frontend/templates/agreements.phtml | 12 +- .../templates/multishipping_agreements.phtml | 12 +- .../adminhtml/templates/browser/content.phtml | 2 +- .../templates/browser/content/files.phtml | 12 +- .../templates/browser/content/uploader.phtml | 12 +- .../adminhtml/templates/browser/tree.phtml | 4 +- .../Cms/view/frontend/templates/content.phtml | 2 +- .../Cms/view/frontend/templates/meta.phtml | 4 +- .../templates/widget/link/link_block.phtml | 2 +- .../templates/widget/link/link_inline.phtml | 2 +- .../widget/static_block/default.phtml | 2 +- .../page/system/config/robots/reset.phtml | 2 +- .../templates/system/config/edit.phtml | 2 +- .../system/config/form/field/array.phtml | 32 ++-- .../templates/system/config/js.phtml | 2 +- .../templates/system/config/switcher.phtml | 8 +- .../templates/system/config/tabs.phtml | 14 +- .../product/attribute/new/created.phtml | 2 +- .../catalog/product/attribute/set/js.phtml | 6 +- .../composite/fieldset/configurable.phtml | 12 +- .../attribute/steps/attributes_values.phtml | 28 ++-- .../product/edit/attribute/steps/bulk.phtml | 112 ++++++------- .../attribute/steps/select_attributes.phtml | 12 +- .../edit/attribute/steps/summary.phtml | 8 +- .../edit/super/associated-product-grid.phtml | 4 +- .../edit/super/attribute-template.phtml | 20 +-- .../catalog/product/edit/super/config.phtml | 24 +-- .../edit/super/manual-product-grid.phtml | 4 +- .../catalog/product/edit/super/matrix.phtml | 36 ++--- .../form.phtml | 10 +- .../affected-attribute-set-selector/js.phtml | 16 +- .../configurable/attribute-selector/js.phtml | 4 +- .../view/type/options/configurable.phtml | 10 +- .../view/frontend/templates/form.phtml | 28 ++-- .../frontend/templates/html/notices.phtml | 16 +- .../frontend/templates/require_cookie.phtml | 2 +- .../view/adminhtml/templates/grid.phtml | 20 +-- .../system/currency/rate/matrix.phtml | 14 +- .../system/currency/rate/services.phtml | 2 +- .../templates/system/currency/rates.phtml | 2 +- .../create/address/form/renderer/vat.phtml | 6 +- .../templates/system/config/validatevat.phtml | 10 +- .../view/adminhtml/templates/tab/cart.phtml | 24 +-- .../templates/tab/view/personal_info.phtml | 32 ++-- .../adminhtml/templates/tab/view/sales.phtml | 32 ++-- .../account/authentication-popup.phtml | 8 +- .../frontend/templates/account/customer.phtml | 2 +- .../templates/account/dashboard/address.phtml | 12 +- .../templates/account/dashboard/info.phtml | 20 +-- .../account/link/authorization.phtml | 4 +- .../templates/account/link/back.phtml | 2 +- .../templates/account/navigation.phtml | 2 +- .../frontend/templates/address/book.phtml | 38 ++--- .../frontend/templates/address/edit.phtml | 76 ++++----- .../templates/form/confirmation.phtml | 10 +- .../view/frontend/templates/form/edit.phtml | 28 ++-- .../templates/form/forgotpassword.phtml | 12 +- .../view/frontend/templates/form/login.phtml | 20 +-- .../frontend/templates/form/newsletter.phtml | 12 +- .../frontend/templates/form/register.phtml | 80 ++++----- .../form/resetforgottenpassword.phtml | 10 +- .../frontend/templates/js/customer-data.phtml | 2 +- .../templates/js/section-config.phtml | 2 +- .../view/frontend/templates/logout.phtml | 4 +- .../view/frontend/templates/newcustomer.phtml | 6 +- .../view/frontend/templates/widget/dob.phtml | 6 +- .../frontend/templates/widget/gender.phtml | 6 +- .../view/frontend/templates/widget/name.phtml | 90 +++++------ .../frontend/templates/widget/taxvat.phtml | 4 +- .../adminhtml/templates/unitofmeasure.phtml | 16 +- .../templates/js/optional_zip_countries.phtml | 4 +- .../view/frontend/templates/currency.phtml | 14 +- .../frontend/templates/currency/switch.phtml | 4 +- .../composite/fieldset/downloadable.phtml | 22 +-- .../templates/product/edit/downloadable.phtml | 2 +- .../product/edit/downloadable/links.phtml | 50 +++--- .../product/edit/downloadable/samples.phtml | 22 +-- .../column/downloadable/creditmemo/name.phtml | 18 +-- .../column/downloadable/invoice/name.phtml | 20 +-- .../items/column/downloadable/name.phtml | 20 +-- .../templates/catalog/product/links.phtml | 24 +-- .../templates/catalog/product/samples.phtml | 4 +- .../templates/catalog/product/type.phtml | 8 +- .../frontend/templates/checkout/success.phtml | 2 +- .../templates/customer/products/list.phtml | 28 ++-- .../order/items/creditmemo/downloadable.phtml | 12 +- .../order/items/invoice/downloadable.phtml | 14 +- .../order/items/order/downloadable.phtml | 22 +-- .../items/renderer/downloadable.phtml | 14 +- .../invoice/items/renderer/downloadable.phtml | 12 +- .../order/items/renderer/downloadable.phtml | 26 +-- .../adminhtml/templates/template/edit.phtml | 30 ++-- .../templates/template/preview.phtml | 2 +- .../adminhtml/templates/giftoptionsform.phtml | 6 +- .../view/adminhtml/templates/popup.phtml | 4 +- .../sales/order/create/giftoptions.phtml | 8 +- .../templates/sales/order/create/items.phtml | 6 +- .../sales/order/view/giftoptions.phtml | 8 +- .../templates/sales/order/view/items.phtml | 16 +- .../templates/cart/gift_options.phtml | 4 +- .../item/renderer/actions/gift_options.phtml | 8 +- .../view/frontend/templates/inline.phtml | 142 ++++++++-------- .../view/frontend/templates/code.phtml | 18 ++- .../view/frontend/templates/ga.phtml | 4 +- .../product/composite/fieldset/grouped.phtml | 34 ++-- .../templates/product/grouped/container.phtml | 12 +- .../templates/product/grouped/grouped.phtml | 4 +- .../templates/product/grouped/list.phtml | 8 +- .../templates/product/price/final_price.phtml | 2 +- .../templates/product/view/type/default.phtml | 8 +- .../templates/product/view/type/grouped.phtml | 20 +-- .../view/adminhtml/templates/busy.phtml | 4 +- .../templates/export/form/after.phtml | 10 +- .../templates/export/form/before.phtml | 2 +- .../templates/import/form/after.phtml | 4 +- .../templates/import/form/before.phtml | 10 +- .../templates/import/frame/result.phtml | 2 +- .../integration/activate/permissions.phtml | 4 +- .../activate/permissions/tab/webapi.phtml | 6 +- .../integration/popup_container.phtml | 16 +- .../integration/tokens_exchange.phtml | 2 +- .../adminhtml/templates/resourcetree.phtml | 10 +- .../frontend/templates/layer/filter.phtml | 12 +- .../view/frontend/templates/layer/state.phtml | 18 +-- .../view/frontend/templates/layer/view.phtml | 8 +- .../system/storage/media/synchronize.phtml | 14 +- .../base/templates/product/price/msrp.phtml | 18 +-- .../frontend/templates/cart/subtotal.phtml | 2 +- .../view/frontend/templates/cart/totals.phtml | 4 +- .../Msrp/view/frontend/templates/popup.phtml | 10 +- .../render/item/price_msrp_item.phtml | 22 +-- .../render/item/price_msrp_rss.phtml | 2 +- .../templates/checkout/address/select.phtml | 14 +- .../templates/checkout/addresses.phtml | 36 ++--- .../frontend/templates/checkout/billing.phtml | 22 +-- .../templates/checkout/billing/items.phtml | 14 +- .../templates/checkout/item/default.phtml | 6 +- .../frontend/templates/checkout/link.phtml | 2 +- .../templates/checkout/overview.phtml | 80 ++++----- .../templates/checkout/overview/item.phtml | 2 +- .../templates/checkout/shipping.phtml | 46 +++--- .../frontend/templates/checkout/state.phtml | 2 +- .../frontend/templates/checkout/success.phtml | 10 +- .../multishipping/item/default.phtml | 6 +- .../templates/preview/iframeswitcher.phtml | 2 +- .../adminhtml/templates/preview/store.phtml | 8 +- .../view/adminhtml/templates/queue/edit.phtml | 6 +- .../adminhtml/templates/queue/preview.phtml | 2 +- .../adminhtml/templates/subscriber/list.phtml | 4 +- .../adminhtml/templates/template/edit.phtml | 24 +-- .../templates/template/preview.phtml | 2 +- .../view/frontend/templates/subscribe.phtml | 10 +- .../templates/form/banktransfer.phtml | 6 +- .../templates/form/cashondelivery.phtml | 6 +- .../adminhtml/templates/form/checkmo.phtml | 4 +- .../templates/form/purchaseorder.phtml | 8 +- .../adminhtml/templates/info/checkmo.phtml | 2 +- .../templates/info/pdf/checkmo.phtml | 2 +- .../templates/form/banktransfer.phtml | 4 +- .../templates/form/cashondelivery.phtml | 4 +- .../frontend/templates/form/checkmo.phtml | 6 +- .../templates/form/purchaseorder.phtml | 6 +- .../frontend/templates/info/checkmo.phtml | 4 +- .../templates/info/purchaseorder.phtml | 2 +- .../view/frontend/templates/javascript.phtml | 2 +- .../view/adminhtml/templates/form/cc.phtml | 70 ++++---- .../adminhtml/templates/info/default.phtml | 2 +- .../templates/info/instructions.phtml | 2 +- .../templates/info/pdf/default.phtml | 4 +- .../templates/transparent/form.phtml | 84 +++++----- .../templates/transparent/iframe.phtml | 4 +- .../templates/transparent/info.phtml | 6 +- .../view/frontend/templates/form/cc.phtml | 56 +++---- .../frontend/templates/info/default.phtml | 2 +- .../templates/info/instructions.phtml | 2 +- .../frontend/templates/transparent/form.phtml | 52 +++--- .../templates/transparent/iframe.phtml | 4 +- .../frontend/templates/transparent/info.phtml | 6 +- .../templates/billing/agreement/form.phtml | 14 +- .../billing/agreement/view/tab/info.phtml | 22 +-- .../payment/form/billing/agreement.phtml | 12 +- .../templates/system/config/api_wizard.phtml | 4 +- .../system/config/bml_api_wizard.phtml | 2 +- .../system/config/fieldset/hint.phtml | 2 +- .../system/config/payflowlink/advanced.phtml | 6 +- .../system/config/payflowlink/info.phtml | 6 +- .../templates/system/config/rules.phtml | 2 +- .../templates/billing/agreement/view.phtml | 50 +++--- .../templates/billing/agreements.phtml | 42 ++--- .../frontend/templates/express/review.phtml | 52 +++--- .../templates/express/review/details.phtml | 10 +- .../express/review/shipping/method.phtml | 12 +- .../frontend/templates/express/shortcut.phtml | 22 +-- .../view/frontend/templates/hss/form.phtml | 10 +- .../view/frontend/templates/hss/iframe.phtml | 4 +- .../view/frontend/templates/hss/info.phtml | 6 +- .../frontend/templates/hss/redirect.phtml | 8 +- .../templates/hss/review/button.phtml | 4 +- .../frontend/templates/partner/logo.phtml | 4 +- .../templates/payflowadvanced/form.phtml | 10 +- .../templates/payflowadvanced/info.phtml | 4 +- .../frontend/templates/payflowlink/form.phtml | 10 +- .../frontend/templates/payflowlink/info.phtml | 6 +- .../templates/payflowlink/redirect.phtml | 8 +- .../payment/form/billing/agreement.phtml | 10 +- .../frontend/templates/payment/mark.phtml | 10 +- .../frontend/templates/payment/redirect.phtml | 10 +- .../view/frontend/templates/remember_me.phtml | 8 +- .../view/frontend/templates/email/price.phtml | 12 +- .../view/frontend/templates/email/stock.phtml | 12 +- .../frontend/templates/product/view.phtml | 2 +- .../view/adminhtml/templates/grid.phtml | 62 +++---- .../templates/report/grid/container.phtml | 2 +- .../adminhtml/templates/report/wishlist.phtml | 14 +- .../adminhtml/templates/store/switcher.phtml | 14 +- .../templates/store/switcher/enhanced.phtml | 12 +- .../templates/product/widget/viewed.phtml | 6 +- .../product/widget/viewed/item.phtml | 34 ++-- .../column/compared_default_list.phtml | 36 ++--- .../column/compared_images_list.phtml | 8 +- .../compared/column/compared_names_list.phtml | 8 +- .../compared/content/compared_grid.phtml | 46 +++--- .../compared/content/compared_list.phtml | 52 +++--- .../viewed/column/viewed_default_list.phtml | 34 ++-- .../viewed/column/viewed_images_list.phtml | 8 +- .../viewed/column/viewed_names_list.phtml | 8 +- .../widget/viewed/content/viewed_grid.phtml | 46 +++--- .../widget/viewed/content/viewed_list.phtml | 52 +++--- .../adminhtml/templates/rating/detailed.phtml | 6 +- .../adminhtml/templates/rating/form.phtml | 2 +- .../adminhtml/templates/rating/options.phtml | 10 +- .../templates/rating/stars/detailed.phtml | 4 +- .../templates/rating/stars/summary.phtml | 4 +- .../adminhtml/templates/rss/grid/link.phtml | 2 +- .../frontend/templates/customer/list.phtml | 28 ++-- .../frontend/templates/customer/recent.phtml | 12 +- .../frontend/templates/customer/view.phtml | 16 +- .../view/frontend/templates/detailed.phtml | 4 +- .../view/frontend/templates/empty.phtml | 4 +- .../Review/view/frontend/templates/form.phtml | 38 ++--- .../frontend/templates/helper/summary.phtml | 14 +- .../templates/helper/summary_short.phtml | 12 +- .../templates/product/view/count.phtml | 2 +- .../templates/product/view/list.phtml | 14 +- .../templates/product/view/other.phtml | 2 +- .../view/frontend/templates/review.phtml | 2 +- .../Review/view/frontend/templates/view.phtml | 18 +-- .../Rss/view/frontend/templates/feeds.phtml | 14 +- .../templates/items/column/name.phtml | 20 +-- .../templates/items/column/qty.phtml | 20 +-- .../adminhtml/templates/items/price/row.phtml | 2 +- .../templates/items/price/total.phtml | 2 +- .../templates/items/price/unit.phtml | 2 +- .../templates/items/renderer/default.phtml | 6 +- .../templates/order/address/form.phtml | 4 +- .../templates/order/comments/view.phtml | 18 +-- .../templates/order/create/abstract.phtml | 2 +- .../order/create/billing/method/form.phtml | 14 +- .../templates/order/create/comment.phtml | 4 +- .../templates/order/create/coupons/form.phtml | 6 +- .../templates/order/create/data.phtml | 16 +- .../templates/order/create/form.phtml | 8 +- .../templates/order/create/form/account.phtml | 4 +- .../templates/order/create/form/address.phtml | 38 ++--- .../templates/order/create/giftmessage.phtml | 4 +- .../templates/order/create/items.phtml | 2 +- .../templates/order/create/items/grid.phtml | 96 +++++------ .../order/create/items/price/row.phtml | 2 +- .../order/create/items/price/total.phtml | 2 +- .../order/create/items/price/unit.phtml | 2 +- .../adminhtml/templates/order/create/js.phtml | 6 +- .../order/create/newsletter/form.phtml | 2 +- .../order/create/shipping/method/form.phtml | 22 +-- .../templates/order/create/sidebar.phtml | 12 +- .../order/create/sidebar/items.phtml | 42 ++--- .../templates/order/create/store/select.phtml | 4 +- .../templates/order/create/totals.phtml | 10 +- .../order/create/totals/default.phtml | 8 +- .../order/create/totals/grandtotal.phtml | 26 +-- .../order/create/totals/shipping.phtml | 30 ++-- .../order/create/totals/subtotal.phtml | 24 +-- .../templates/order/create/totals/tax.phtml | 18 +-- .../order/creditmemo/create/form.phtml | 16 +- .../order/creditmemo/create/items.phtml | 40 ++--- .../create/items/renderer/default.phtml | 12 +- .../create/totals/adjustments.phtml | 14 +- .../order/creditmemo/view/form.phtml | 24 +-- .../order/creditmemo/view/items.phtml | 18 +-- .../view/items/renderer/default.phtml | 6 +- .../adminhtml/templates/order/details.phtml | 40 ++--- .../templates/order/giftoptions.phtml | 2 +- .../templates/order/invoice/create/form.phtml | 22 +-- .../order/invoice/create/items.phtml | 46 +++--- .../create/items/renderer/default.phtml | 10 +- .../templates/order/invoice/view/form.phtml | 22 +-- .../templates/order/invoice/view/items.phtml | 16 +- .../invoice/view/items/renderer/default.phtml | 6 +- .../adminhtml/templates/order/totalbar.phtml | 4 +- .../adminhtml/templates/order/totals.phtml | 20 +-- .../templates/order/totals/discount.phtml | 6 +- .../templates/order/totals/due.phtml | 4 +- .../templates/order/totals/grand.phtml | 6 +- .../templates/order/totals/item.phtml | 4 +- .../templates/order/totals/paid.phtml | 4 +- .../templates/order/totals/refunded.phtml | 4 +- .../templates/order/totals/shipping.phtml | 4 +- .../templates/order/totals/tax.phtml | 14 +- .../templates/order/view/giftmessage.phtml | 26 +-- .../templates/order/view/history.phtml | 26 +-- .../adminhtml/templates/order/view/info.phtml | 82 +++++----- .../templates/order/view/items.phtml | 22 +-- .../order/view/items/renderer/default.phtml | 10 +- .../templates/order/view/tab/history.phtml | 24 +-- .../templates/order/view/tab/info.phtml | 16 +- .../templates/rss/order/grid/link.phtml | 2 +- .../templates/transactions/detail.phtml | 20 +-- .../templates/email/creditmemo/items.phtml | 6 +- .../templates/email/invoice/items.phtml | 6 +- .../view/frontend/templates/email/items.phtml | 14 +- .../email/items/creditmemo/default.phtml | 10 +- .../email/items/invoice/default.phtml | 10 +- .../templates/email/items/order/default.phtml | 18 +-- .../templates/email/items/price/row.phtml | 2 +- .../email/items/shipment/default.phtml | 8 +- .../templates/email/shipment/items.phtml | 4 +- .../templates/email/shipment/track.phtml | 4 +- .../view/frontend/templates/guest/form.phtml | 22 +-- .../frontend/templates/items/price/row.phtml | 2 +- .../items/price/total_after_discount.phtml | 2 +- .../frontend/templates/items/price/unit.phtml | 2 +- .../frontend/templates/order/comments.phtml | 4 +- .../frontend/templates/order/creditmemo.phtml | 4 +- .../templates/order/creditmemo/items.phtml | 28 ++-- .../creditmemo/items/renderer/default.phtml | 14 +- .../frontend/templates/order/history.phtml | 30 ++-- .../view/frontend/templates/order/info.phtml | 16 +- .../templates/order/info/buttons.phtml | 8 +- .../templates/order/info/buttons/rss.phtml | 4 +- .../frontend/templates/order/invoice.phtml | 4 +- .../templates/order/invoice/items.phtml | 24 +-- .../invoice/items/renderer/default.phtml | 10 +- .../view/frontend/templates/order/items.phtml | 38 ++--- .../order/items/renderer/default.phtml | 24 +-- .../templates/order/order_comments.phtml | 4 +- .../frontend/templates/order/order_date.phtml | 2 +- .../templates/order/order_status.phtml | 2 +- .../templates/order/print/creditmemo.phtml | 34 ++-- .../templates/order/print/invoice.phtml | 32 ++-- .../templates/order/print/shipment.phtml | 22 +-- .../frontend/templates/order/recent.phtml | 36 ++--- .../shipment/items/renderer/default.phtml | 10 +- .../frontend/templates/order/totals.phtml | 10 +- .../view/frontend/templates/order/view.phtml | 14 +- .../frontend/templates/reorder/sidebar.phtml | 18 +-- .../templates/widget/guest/form.phtml | 20 +-- .../templates/promo/salesrulejs.phtml | 2 +- .../view/frontend/templates/form.mini.phtml | 20 +-- .../Search/view/frontend/templates/term.phtml | 6 +- .../view/frontend/templates/send.phtml | 40 ++--- .../adminhtml/templates/create/form.phtml | 16 +- .../adminhtml/templates/create/items.phtml | 30 ++-- .../create/items/renderer/default.phtml | 10 +- .../templates/order/Tracking/view.phtml | 20 +-- .../templates/order/packaging/grid.phtml | 32 ++-- .../templates/order/packaging/packed.phtml | 76 ++++----- .../templates/order/packaging/popup.phtml | 88 +++++----- .../adminhtml/templates/order/tracking.phtml | 12 +- .../adminhtml/templates/order/view/info.phtml | 10 +- .../view/adminhtml/templates/view/form.phtml | 30 ++-- .../view/adminhtml/templates/view/items.phtml | 6 +- .../view/items/renderer/default.phtml | 2 +- .../view/frontend/templates/items.phtml | 32 ++-- .../frontend/templates/order/shipment.phtml | 4 +- .../frontend/templates/tracking/link.phtml | 6 +- .../frontend/templates/tracking/popup.phtml | 72 ++++----- .../frontend/templates/switch/flags.phtml | 6 +- .../frontend/templates/switch/languages.phtml | 12 +- .../frontend/templates/switch/stores.phtml | 4 +- .../frontend/templates/swagger-ui/index.phtml | 2 +- .../catalog/product/attribute/js.phtml | 4 +- .../catalog/product/attribute/text.phtml | 26 +-- .../catalog/product/attribute/visual.phtml | 28 ++-- .../templates/product/layered/renderer.phtml | 42 ++--- .../templates/product/listing/renderer.phtml | 12 +- .../templates/product/view/renderer.phtml | 6 +- .../adminhtml/templates/class/page/edit.phtml | 2 +- .../adminhtml/templates/items/price/row.phtml | 8 +- .../templates/items/price/total.phtml | 2 +- .../templates/items/price/unit.phtml | 8 +- .../order/create/items/price/row.phtml | 8 +- .../order/create/items/price/total.phtml | 8 +- .../order/create/items/price/unit.phtml | 8 +- .../view/adminhtml/templates/rate/js.phtml | 2 +- .../view/adminhtml/templates/rate/title.phtml | 6 +- .../view/adminhtml/templates/rule/edit.phtml | 38 ++--- .../adminhtml/templates/rule/rate/form.phtml | 2 +- .../templates/toolbar/class/add.phtml | 4 +- .../templates/toolbar/class/save.phtml | 2 +- .../templates/toolbar/rate/save.phtml | 2 +- .../templates/toolbar/rule/add.phtml | 4 +- .../templates/toolbar/rule/save.phtml | 2 +- .../base/templates/pricing/adjustment.phtml | 6 +- .../templates/pricing/adjustment/bundle.phtml | 8 +- .../checkout/cart/item/price/sidebar.phtml | 8 +- .../templates/checkout/grandtotal.phtml | 26 +-- .../templates/checkout/shipping.phtml | 30 ++-- .../templates/checkout/shipping/price.phtml | 8 +- .../templates/checkout/subtotal.phtml | 24 +-- .../frontend/templates/checkout/tax.phtml | 20 +-- .../templates/email/items/price/row.phtml | 8 +- .../frontend/templates/item/price/row.phtml | 4 +- .../item/price/total_after_discount.phtml | 2 +- .../frontend/templates/item/price/unit.phtml | 4 +- .../view/frontend/templates/order/tax.phtml | 18 +-- .../adminhtml/templates/importExport.phtml | 8 +- .../adminhtml/templates/browser/content.phtml | 2 +- .../templates/browser/content/files.phtml | 8 +- .../templates/browser/content/uploader.phtml | 10 +- .../view/adminhtml/templates/tabs/css.phtml | 2 +- .../templates/tabs/fieldset/js.phtml | 6 +- .../view/adminhtml/templates/tabs/js.phtml | 2 +- .../view/adminhtml/templates/title.phtml | 6 +- .../Theme/view/base/templates/root.phtml | 14 +- .../templates/callouts/left_col.phtml | 6 +- .../templates/callouts/right_col.phtml | 6 +- .../view/frontend/templates/html/block.phtml | 6 +- .../frontend/templates/html/breadcrumbs.phtml | 4 +- .../frontend/templates/html/bugreport.phtml | 4 +- .../frontend/templates/html/collapsible.phtml | 8 +- .../frontend/templates/html/copyright.phtml | 2 +- .../view/frontend/templates/html/footer.phtml | 6 +- .../frontend/templates/html/header/logo.phtml | 8 +- .../frontend/templates/html/notices.phtml | 10 +- .../view/frontend/templates/html/pager.phtml | 52 +++--- .../frontend/templates/html/sections.phtml | 10 +- .../view/frontend/templates/html/skip.phtml | 4 +- .../frontend/templates/html/skiptarget.phtml | 2 +- .../view/frontend/templates/html/title.phtml | 8 +- .../frontend/templates/html/topmenu.phtml | 2 +- .../view/frontend/templates/js/calendar.phtml | 30 ++-- .../view/frontend/templates/js/cookie.phtml | 6 +- .../templates/translate_inline.phtml | 8 +- .../view/base/templates/translate.phtml | 2 +- .../frontend/templates/translate_inline.phtml | 10 +- .../templates/control/button/default.phtml | 4 +- .../Ui/view/base/templates/form/default.phtml | 8 +- .../view/base/templates/label/default.phtml | 2 +- .../base/templates/layout/tabs/default.phtml | 2 +- .../templates/layout/tabs/nav/default.phtml | 2 +- .../Ui/view/base/templates/logger.phtml | 2 +- .../Ui/view/base/templates/stepswizard.phtml | 24 +-- .../system/shipping/carrier_config.phtml | 12 +- .../view/adminhtml/templates/categories.phtml | 2 +- .../view/adminhtml/templates/edit.phtml | 2 +- .../view/adminhtml/templates/selector.phtml | 4 +- .../templates/admin/forgotpassword.phtml | 14 +- .../templates/admin/forgotpassword_url.phtml | 2 +- .../admin/resetforgottenpassword.phtml | 14 +- .../view/adminhtml/templates/role/edit.phtml | 10 +- .../view/adminhtml/templates/role/info.phtml | 2 +- .../view/adminhtml/templates/role/users.phtml | 2 +- .../templates/role/users_grid_js.phtml | 20 +-- .../templates/user/roles_grid_js.phtml | 14 +- .../adminhtml/templates/items/price/row.phtml | 12 +- .../templates/items/price/total.phtml | 2 +- .../templates/items/price/unit.phtml | 12 +- .../order/create/items/price/row.phtml | 20 +-- .../order/create/items/price/total.phtml | 20 +-- .../order/create/items/price/unit.phtml | 20 +-- .../adminhtml/templates/renderer/tax.phtml | 36 ++--- .../base/templates/pricing/adjustment.phtml | 8 +- .../checkout/cart/item/price/sidebar.phtml | 16 +- .../review/item/price/row_excl_tax.phtml | 14 +- .../review/item/price/row_incl_tax.phtml | 14 +- .../review/item/price/unit_excl_tax.phtml | 14 +- .../review/item/price/unit_incl_tax.phtml | 14 +- .../templates/email/items/price/row.phtml | 16 +- .../frontend/templates/item/price/row.phtml | 28 ++-- .../item/price/total_after_discount.phtml | 2 +- .../frontend/templates/item/price/unit.phtml | 28 ++-- .../catalog/category/widget/tree.phtml | 30 ++-- .../templates/instance/edit/layout.phtml | 72 ++++----- .../customer/edit/tab/wishlist.phtml | 12 +- .../frontend/templates/button/share.phtml | 4 +- .../frontend/templates/button/tocart.phtml | 4 +- .../frontend/templates/button/update.phtml | 4 +- .../renderer/actions/move_to_wishlist.phtml | 4 +- .../view/frontend/templates/email/items.phtml | 12 +- .../templates/item/column/actions.phtml | 4 +- .../frontend/templates/item/column/cart.phtml | 20 +-- .../templates/item/column/comment.phtml | 6 +- .../frontend/templates/item/column/edit.phtml | 4 +- .../templates/item/column/image.phtml | 2 +- .../frontend/templates/item/column/name.phtml | 2 +- .../templates/item/column/price.phtml | 2 +- .../templates/item/column/remove.phtml | 4 +- .../templates/item/configure/addto.phtml | 10 +- .../view/frontend/templates/item/list.phtml | 4 +- .../view/frontend/templates/link.phtml | 2 +- .../frontend/templates/options_list.phtml | 8 +- .../view/frontend/templates/rss/email.phtml | 2 +- .../frontend/templates/rss/wishlist.phtml | 4 +- .../view/frontend/templates/shared.phtml | 36 ++--- .../view/frontend/templates/sharing.phtml | 24 +-- .../view/frontend/templates/sidebar.phtml | 18 +-- .../view/frontend/templates/view.phtml | 12 +- .../templates/layer/state.phtml | 20 +-- .../templates/layer/view.phtml | 14 +- .../Utility/XssOutputValidator.php | 38 ++++- .../Utility/_files/xss_safe.phtml | 1 + 762 files changed, 5838 insertions(+), 5709 deletions(-) diff --git a/app/code/Magento/AdminNotification/view/adminhtml/templates/notification/window.phtml b/app/code/Magento/AdminNotification/view/adminhtml/templates/notification/window.phtml index cfe907830dbc3..51fa6d1a05ebd 100644 --- a/app/code/Magento/AdminNotification/view/adminhtml/templates/notification/window.phtml +++ b/app/code/Magento/AdminNotification/view/adminhtml/templates/notification/window.phtml @@ -13,19 +13,19 @@ */ ?>
- diff --git a/app/code/Magento/AdminNotification/view/adminhtml/templates/system/messages.phtml b/app/code/Magento/AdminNotification/view/adminhtml/templates/system/messages.phtml index 784e229f9a57f..fcfa262be72d9 100644 --- a/app/code/Magento/AdminNotification/view/adminhtml/templates/system/messages.phtml +++ b/app/code/Magento/AdminNotification/view/adminhtml/templates/system/messages.phtml @@ -15,19 +15,19 @@
- + getCriticalCount()): ?> @@ -35,7 +35,7 @@ getMajorCount()): ?> diff --git a/app/code/Magento/AdminNotification/view/adminhtml/templates/system/messages/popup.phtml b/app/code/Magento/AdminNotification/view/adminhtml/templates/system/messages/popup.phtml index 3652e763a1c9b..589c26fa8c373 100644 --- a/app/code/Magento/AdminNotification/view/adminhtml/templates/system/messages/popup.phtml +++ b/app/code/Magento/AdminNotification/view/adminhtml/templates/system/messages/popup.phtml @@ -12,8 +12,8 @@
    getUnreadMessages() as $message): ?> -
  • - getText();?> +
  • + getText();?>
diff --git a/app/code/Magento/AdminNotification/view/adminhtml/templates/toolbar_entry.phtml b/app/code/Magento/AdminNotification/view/adminhtml/templates/toolbar_entry.phtml index e020a661d4d91..b86a2f2246a2a 100644 --- a/app/code/Magento/AdminNotification/view/adminhtml/templates/toolbar_entry.phtml +++ b/app/code/Magento/AdminNotification/view/adminhtml/templates/toolbar_entry.phtml @@ -15,25 +15,25 @@
+ data-notification-count=""> 0) : ?> - $notificationCounterMax) ? $notificationCounterMax . '+' : $notificationCount; ?> + $notificationCounterMax) ? $notificationCounterMax . '+' : $notificationCount; ?>
    + data-mark-as-read-url="getUrl('adminhtml/notification/ajaxMarkAsRead'); ?>"> getLatestUnreadNotifications() as $notification) : ?>
  • escapeHtml($notification->getDescription()); @@ -45,40 +45,40 @@ $notificationDescriptionLength) : ?>

    - + - +

    - +

  • - +
+ href="getUrl('adminhtml/notification/index'); ?>" + title="">
diff --git a/app/code/Magento/Authorizenet/view/adminhtml/templates/directpost/iframe.phtml b/app/code/Magento/Authorizenet/view/adminhtml/templates/directpost/iframe.phtml index 23c1438d777bc..2712012849971 100644 --- a/app/code/Magento/Authorizenet/view/adminhtml/templates/directpost/iframe.phtml +++ b/app/code/Magento/Authorizenet/view/adminhtml/templates/directpost/iframe.phtml @@ -22,9 +22,9 @@ $helper = $block->getHelper('adminhtml'); window.top.location="escapeUrl($params['redirect_parent']) ?>"; - window.top.directPostModel.showError(); + window.top.directPostModel.showError(); - window.top.directPostModel.successUrl="getSuccessOrderUrl($params) ?>"; + window.top.directPostModel.successUrl="getSuccessOrderUrl($params) ?>"; diff --git a/app/code/Magento/Authorizenet/view/adminhtml/templates/directpost/info.phtml b/app/code/Magento/Authorizenet/view/adminhtml/templates/directpost/info.phtml index 586d6ff403ebc..adff03b5365c2 100644 --- a/app/code/Magento/Authorizenet/view/adminhtml/templates/directpost/info.phtml +++ b/app/code/Magento/Authorizenet/view/adminhtml/templates/directpost/info.phtml @@ -18,71 +18,71 @@ $_controller = $block->getRequest()->getControllerName(); $_orderUrl = $this->helper('Magento\Authorizenet\Helper\Backend\Data')->getPlaceOrderAdminUrl(); ?> - + - -