88/**
99 * @var $block Magento\Shipping\Block\Adminhtml\Order\Tracking
1010 * @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer
11+ * @var $escaper \Magento\Framework\Escaper
1112 */
1213?>
1314<?php $ scriptString = <<<script
@@ -76,7 +77,7 @@ script;
7677 class="select admin__control-select carrier"
7778 disabled="disabled">
7879 <?php foreach ($ block ->getCarriers () as $ _code => $ _name ): ?>
79- <option value="<?= $ block ->escapeHtmlAttr ($ _code ) ?> "><?= $ block ->escapeHtml ($ _name ) ?> </option>
80+ <option value="<?= $ escaper ->escapeHtmlAttr ($ _code ) ?> "><?= $ escaper ->escapeHtml ($ _name ) ?> </option>
8081 <?php endforeach ; ?>
8182 </select>
8283 </td>
@@ -101,7 +102,7 @@ script;
101102 type="button"
102103 class="action-default action-delete"
103104 onclick="trackingControl.deleteRow(event);return false">
104- <span><?= $ block ->escapeHtml (__ ('Delete ' )) ?> </span>
105+ <span><?= $ escaper ->escapeHtml (__ ('Delete ' )) ?> </span>
105106 </button>
106107 </td>
107108 </tr>
@@ -111,10 +112,10 @@ script;
111112 <table class="data-table admin__control-table" id="tracking_numbers_table">
112113 <thead>
113114 <tr class="headings">
114- <th class="col-carrier"><?= $ block ->escapeHtml (__ ('Carrier ' )) ?> </th>
115- <th class="col-title"><?= $ block ->escapeHtml (__ ('Title ' )) ?> </th>
116- <th class="col-number"><?= $ block ->escapeHtml (__ ('Number ' )) ?> </th>
117- <th class="col-delete"><?= $ block ->escapeHtml (__ ('Action ' )) ?> </th>
115+ <th class="col-carrier"><?= $ escaper ->escapeHtml (__ ('Carrier ' )) ?> </th>
116+ <th class="col-title"><?= $ escaper ->escapeHtml (__ ('Title ' )) ?> </th>
117+ <th class="col-number"><?= $ escaper ->escapeHtml (__ ('Number ' )) ?> </th>
118+ <th class="col-delete"><?= $ escaper ->escapeHtml (__ ('Action ' )) ?> </th>
118119 </tr>
119120 </thead>
120121 <tfoot>
0 commit comments