From 275c3e93eba7c4532790bd6f753d5ad765348833 Mon Sep 17 00:00:00 2001
From: "Yushkin, Dmytro" <dyushkin@ebay.com>
Date: Thu, 22 Oct 2015 12:42:42 +0300
Subject: [PATCH] MAGETWO-44299: Verify @noEscape outputs for shipment and
 payments modules

- Fix by code review
---
 .../view/frontend/templates/express/review.phtml       | 10 ++++------
 .../templates/express/review/shipping/method.phtml     |  4 ++--
 2 files changed, 6 insertions(+), 8 deletions(-)

diff --git a/app/code/Magento/Paypal/view/frontend/templates/express/review.phtml b/app/code/Magento/Paypal/view/frontend/templates/express/review.phtml
index 5d3c0b5c720..9146130881c 100644
--- a/app/code/Magento/Paypal/view/frontend/templates/express/review.phtml
+++ b/app/code/Magento/Paypal/view/frontend/templates/express/review.phtml
@@ -42,8 +42,8 @@
                                                             <?php echo($currentRate === $rate) ?
                                                                 ' selected="selected"' : '';
                                                             ?>>
-                                                            <?php echo
-                                                                $block->escapeHtml($block->renderShippingRateOption($rate));
+                                                            <?php /* @noEscape */ echo
+                                                                $block->renderShippingRateOption($rate);
                                                             ?>
                                                         </option>
                                                     <?php endforeach; ?>
@@ -70,10 +70,8 @@
                                 <?php endif; ?>
                             <?php else: ?>
                                 <p>
-                                    <?php echo $block->escapeHtml(
-                                        $block->renderShippingRateOption(
-                                            $block->getCurrentShippingRate()
-                                        )
+                                    <?php /* @noEscape */ echo $block->renderShippingRateOption(
+                                        $block->getCurrentShippingRate()
                                     ); ?>
                                 </p>
                             <?php endif; ?>
diff --git a/app/code/Magento/Paypal/view/frontend/templates/express/review/shipping/method.phtml b/app/code/Magento/Paypal/view/frontend/templates/express/review/shipping/method.phtml
index ce8952a08d3..909d0e1c762 100644
--- a/app/code/Magento/Paypal/view/frontend/templates/express/review/shipping/method.phtml
+++ b/app/code/Magento/Paypal/view/frontend/templates/express/review/shipping/method.phtml
@@ -24,7 +24,7 @@
                             <option
                                 value="<?php echo $block->escapeHtml($block->renderShippingRateValue($rate)); ?>"
                                     <?php echo($currentRate === $rate) ? ' selected="selected"' : ''; ?>>
-                                <?php echo $block->escapeHtml($block->renderShippingRateOption($rate)); ?>
+                                <?php /* @noEscape */ echo $block->renderShippingRateOption($rate); ?>
                             </option>
                         <?php endforeach; ?>
                     </optgroup>
@@ -40,7 +40,7 @@
     <?php else: ?>
         <p>
             <strong>
-                <?php echo $block->escapeHtml($block->renderShippingRateOption($block->getCurrentShippingRate())); ?>
+                <?php /* @noEscape */ echo $block->renderShippingRateOption($block->getCurrentShippingRate()); ?>
             </strong>
         </p>
     <?php endif; ?>
-- 
GitLab